A Systematic Process-Model-based Approach for Synthesizing Attacks and Evaluating Them

نویسندگان

  • Huong Phan
  • George S. Avrunin
  • Matt Bishop
  • Lori A. Clarke
  • Leon J. Osterweil
چکیده

This paper describes a systematic approach for incrementally improving the security of election processes by using a model of the process to develop attack plans and then incorporating each plan into the process model to determine if it can complete successfully. More specifically, our approach first applies fault tree analysis to a detailed election process model to find process vulnerabilities that an adversary might be able to exploit, thus identifying potential attacks. Based on such a vulnerability, we then model an attack plan and formally evaluate the process’s robustness against such a plan. If appropriate, we also propose modifications to the process and then reapply the approach to ensure that the attack will not succeed. Although the approach is described in the context of the election domain, it would also seem to be effective in analyzing process vulnerability in other domains.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

BotRevealer: Behavioral Detection of Botnets based on Botnet Life-cycle

Nowadays, botnets are considered as essential tools for planning serious cyberattacks. Botnets are used to perform various malicious activities such as DDoSattacks and sending spam emails. Different approaches are presented to detectbotnets; however most of them may be ineffective when there are only a fewinfected hosts in monitored network, as they rely on similarity in...

متن کامل

A risk model for cloud processes

Traditionally, risk assessment consists of evaluating the probability of "feared events", corresponding to known threats and attacks, as well as these events' severity, corresponding to their impact on one or more stakeholders. Assessing risks of cloud-based processes is particularly difficult due to lack of historical data on attacks, which has prevented frequency-based identification...

متن کامل

Developing a conceptual model based upon the Latin Hypercube Sampling for integrating OHS into project risk evaluation

Abstract Project management in construction industry, in many cases, is imperfect with respect to the integration of Occupational Health and Safety (OHS) risks. This imperfection exhibits itself as complications affecting the riskiness of industrial procedures and is illustrated usually by poor awareness of OHS within project teams. Difficulties on OHS regularly came about in the construction i...

متن کامل

Comparative Approach to the Backward Elimination and for-ward Selection Methods in Modeling the Systematic Risk Based on the ARFIMA-FIGARCH Model

The present study aims to model systematic risk using financial and accounting variables. Accordingly, the data for 174 companies in Tehran Stock Exchange are extracted for the period of 2006 to 2016. First, the systematic risk index is estimated using the ARFIMA-FIGARCH model. Then, based on the research background, 35 affective financial and accounting variables are simultaneously used with t...

متن کامل

Providing a Mathematical Model for Evaluating Resilient Suppliers and Order Allocation in Automotive Related Industries

Today's supply chains are faced with many challenges and threats such as natural disasters, cyber-attacks, boycotts, disruptions in supply, production and distribution, etc. So selection of resilience supplier can significantly reduce purchasing costs and lead times and increase the business continuity in case of disruptions. The aim of this study is evaluating the suppliers and selecting best ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2012