【24h】

Formalizing Threat Models for Virtualized Systems

机译:虚拟化系统的正式威胁模型

获取原文

摘要

We propose a framework, called FATHoM (FormAlizing THreat Models), to define threat models for virtualized systems. For each component of a virtualized system, we specify a set of security properties that defines its control responsibility, its vulnerability and protection states. Relations are used to represent how assumptions made about a component's security state restrict the assumptions that can be made on the other components. FATHoM includes a set of rules to compute the derived security states from the assumptions and the components' relations. A further set of relations and rules is used to define how to protect the derived vulnerable components. The resulting system is then analysed, among others, for consistency of the threat model. We have developed a tool that implements FATHoM, and have validated it with use-cases adapted from the literature.
机译:我们提出了一个称为FATHoM(正式威胁模型)的框架,用于定义虚拟化系统的威胁模型。对于虚拟化系统的每个组件,我们指定一组安全属性,这些属性定义其控制责任,脆弱性和保护状态。关系用于表示对组件安全状态所做的假设如何限制可以对其他组件进行的假设。 FATHoM包括一组规则,用于根据假设和组件之间的关系来计算派生的安全状态。另一组关系和规则用于定义如何保护派生的易受攻击的组件。然后分析所得系统,以确保威胁模型的一致性。我们已经开发了一种实现FATHoM的工具,并已根据文献中的用例对其进行了验证。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号