【24h】

Goal-Driven Deception Tactics Design

机译:目标驱动的欺骗策略设计

获取原文

摘要

Deception-based defense relies on intentional actions employed to induce erroneous inferences on attackers. Existing deception approaches are included in the software development process in an ad-hoc fashion, and are fundamentally realized as single tools or entire solutions repackaged as honeypot machines. We propose a systematic goal-driven approach to include deception tactics early in the software development process so that conflicts and risks can be found in the initial phases of the development, reducing costs of ill-planed decisions. The process integrates three phases: system modeling (producing a goal model of the application domain), security modeling (producing a threat model specifying the typical security concerns from the attacker perspective), and deception modeling (producing a deception tactic model, a variability model, and deception story models). The feasibility of the proposed approach is shown via a case study where deception defense strategies are designed for a students' presence control system for our University.
机译:基于欺骗的防御依赖于旨在对攻击者进行错误推断的故意行为。现有的欺骗方法以特殊方式包含在软件开发过程中,并且从根本上实现为单个工具或整个解决方案,重新包装为蜜罐机。我们提出一种系统的目标驱动方法,在软件开发过程的早期就包括欺骗策略,以便可以在开发的初始阶段发现冲突和风险,从而减少计划不周的决策的成本。该过程集成了三个阶段:系统建模(生成应用程序域的目标模型),安全建模(生成从攻击者角度指定典型安全问题的威胁模型)和欺骗建模(生成欺骗策略模型,可变性模型) ,以及欺骗故事模型)。通过案例研究证明了该方法的可行性,在该案例研究中,为我们大学的学生存在控制系统设计了欺骗防御策略。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号