Drake Patrick Mirembe
Threat Modeling Revisited: Improving Expressiveness of Attack
Mirembe, Drake Patrick; Muyeba, Maybin
Abstract
Threat modeling plays an important role in the deployment of optimal security controls and a number of threat modeling techniques have been proposed. However, most of the existing techniques lack adequate semantics and expressiveness. This paper reviews the existing techniques and proposes threat net; a technique based on information and causality theory concepts which offers improved expressiveness and semantics of threat models. Threat net is built on Petri nets and treats every node in the threat path as a random variable, whose values include time specific attacker profile and system defense capabilities. In theory, by computing the expected value of random events one can estimate the cost of achieving a given goal. We believe that the simplicity and richness of our technique will make it attractive to security experts. In future we hope to validate threat net using case-based analysis theory.
Presentation Conference Type | Conference Paper (published) |
---|---|
Conference Name | 2008 Second UKSIM European Symposium on Computer Modeling and Simulation (EMS) |
Start Date | Sep 8, 2008 |
End Date | Sep 10, 2008 |
Publication Date | 2008-09 |
Deposit Date | Apr 2, 2025 |
Publisher | Institute of Electrical and Electronics Engineers |
Peer Reviewed | Peer Reviewed |
Pages | 93-98 |
ISBN | 978-0-7695-3325-4 |
DOI | https://doi.org/10.1109/ems.2008.83 |
Keywords | Threat Net , Expressiveness , Semantics , Petri Nets , Threat-Centric , Attack-Centric |
You might also like
Attention is Everything You Need: Case on Face Mask Classification
(2023)
Journal Article
A hybrid heuristic approach for attribute-oriented mining
(2013)
Journal Article
Business information query expansion through semantic network
(2010)
Journal Article
Fuzzy Weighted Association Rule Mining with Weighted Support and Confidence Framework
(2009)
Presentation / Conference Contribution
A Method for Web Information Extraction
(2008)
Presentation / Conference Contribution
Downloadable Citations
About USIR
Administrator e-mail: library-research@salford.ac.uk
This application uses the following open-source libraries:
SheetJS Community Edition
Apache License Version 2.0 (http://www.apache.org/licenses/)
PDF.js
Apache License Version 2.0 (http://www.apache.org/licenses/)
Font Awesome
SIL OFL 1.1 (http://scripts.sil.org/OFL)
MIT License (http://opensource.org/licenses/mit-license.html)
CC BY 3.0 ( http://creativecommons.org/licenses/by/3.0/)
Powered by Worktribe © 2025
Advanced Search