...
首页> 外文期刊>Systems Engineering >Model-driven architecture based security analysis
【24h】

Model-driven architecture based security analysis

机译:基于模型驱动的架构的安全分析

获取原文
获取原文并翻译 | 示例
           

摘要

This paper proposes a Model-Driven Architecture approach for the development of an embedded system validation platform namely Model-Based Security Analysis for Embedded Systems (MBSAES). The security properties are formally modeled and verified at an early stage of the design process of the system, which helps to reduce late errors and development time. A separation of the attack scenarios and the system design from the implementation details has been respected. To transform semi-formal models from SysML to NuSVM model checking platform, two Model-to-Text, horizontal and exogenous transformations have been implemented. The first one employs a programming approach with Java to create a Computational Tree Logic specification from an Extended Attack Tree, whereas the second one uses a template approach with Acceleo to generate NuSMV code from SysML structural and behavioral models. To illustrate our approach, a case study, involving attacks aiming to unlock car door systems, via signal jamming and code replaying, is considered. The results of this research will contribute to the automatic validation of system designs against security vulnerabilities via a database of extended attack trees building from existing atomic attacks.
机译:本文提出了一种模型驱动的架构方法,用于开发嵌入式系统验证平台的嵌入式系统的模型安全性分析(MBSAE)。安全性属性在系统的设计过程的早期阶段正式建模和验证,有助于降低迟到的错误和开发时间。从实现细节中攻击攻击方案和系统设计的分离已得到尊重。要将SYSML转换为NUSVM模型检查平台的半正式模型,已经实施了两个模型,水平和外源性转换。第一个使用Java的编程方法来从扩展攻击树创建计算树逻辑规范,而第二个则使用模板方法与Acceleo一起生成来自Sysml结构和行为模型的NUSMV码。为了说明我们的方法,考虑涉及旨在通过信号干扰和代码重放来解锁车门系统的攻击的案例研究。本研究的结果将有助于通过从现有原子攻击的扩展攻击树建筑物的数据库自动验证对安全漏洞的安全漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号