Quantitative Security Risk Modeling and Analysis with RisQFLan
Maurice H. ter Beek, Axel Legay, Alberto Lluch Lafuente, Andrea Vandin

TL;DR
This paper introduces RisQFLan, a novel tool-supported framework that extends QFLan for quantitative security risk modeling using attack-defense trees, enabling precise and statistical analysis of probabilistic attack scenarios.
Contribution
It presents RisQFLan, a new framework that integrates features from various attack tree types into a domain-specific language for enhanced security risk analysis.
Findings
Supports exact and statistical verification of attack scenarios.
Demonstrated through three illustrative case studies.
Enhances existing security risk modeling tools.
Abstract
Domain-specific quantitative modeling and analysis approaches are fundamental in scenarios in which qualitative approaches are inappropriate or unfeasible. In this paper, we present a tool-supported approach to quantitative graph-based security risk modeling and analysis based on attack-defense trees. Our approach is based on QFLan, a successful domain-specific approach to support quantitative modeling and analysis of highly configurable systems, whose domain-specific components have been decoupled to facilitate the instantiation of the QFLan approach in the domain of graph-based security risk modeling and analysis. Our approach incorporates distinctive features from three popular kinds of attack trees, namely enhanced attack trees, capabilities-based attack trees and attack countermeasure trees, into the domain-specific modeling language. The result is a new framework, called RisQFLan,…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Software Reliability and Analysis Research · Advanced Software Engineering Methodologies
