Formalising Systematic Security Evaluations Using Attack Trees for Automotive Applications - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2018

Formalising Systematic Security Evaluations Using Attack Trees for Automotive Applications

Madeline Cheah
  • Fonction : Auteur
  • PersonId : 1036527
Hoang Nga Nguyen
  • Fonction : Auteur
  • PersonId : 1023221
Jeremy Bryans
  • Fonction : Auteur
  • PersonId : 1023220
Siraj A. Shaikh
  • Fonction : Auteur
  • PersonId : 1023219

Résumé

Vehicles are insecure. To protect such systems, we must begin by identifying any weaknesses. One approach is to apply a systematic security evaluation to the system under test. In this paper we present a method for systematically generating tests based on attack trees. We formalise the attack trees as provably-equivalent process-algebraic processes, then automatically generate tests from the process-algebraic representation. Attack trees may include manual input (and thus so will some test cases) but scriptable test cases are automatically executed. Our approach is inspired by model based testing, but allows for the fact that we do not have a specification of the system under test. We demonstrate this methodology on a case study and find that this is a viable method for automation of systematic security evaluations.
Fichier principal
Vignette du fichier
469589_1_En_7_Chapter.pdf (379.11 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01875515 , version 1 (17-09-2018)

Licence

Paternité

Identifiants

Citer

Madeline Cheah, Hoang Nga Nguyen, Jeremy Bryans, Siraj A. Shaikh. Formalising Systematic Security Evaluations Using Attack Trees for Automotive Applications. 11th IFIP International Conference on Information Security Theory and Practice (WISTP), Sep 2017, Heraklion, Greece. pp.113-129, ⟨10.1007/978-3-319-93524-9_7⟩. ⟨hal-01875515⟩
60 Consultations
143 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More