Contextualisation of Data Flow Diagrams for security analysis

06/07/2020
by   Shamal Faily, et al.
0

Data flow diagrams (DFDs) are popular for sketching systems for subsequent threat modelling. Their limited semantics make reasoning about them difficult, but enriching them endangers their simplicity and subsequent ease of take up. We present an approach for reasoning about tainted data flows in design-level DFDs by putting them in context with other complementary usability and requirements models. We illustrate our approach using a pilot study, where tainted data flows were identified without any augmentations to either the DFD or its complementary models.

READ FULL TEXT
research
05/09/2022

Compositional Modeling with Stock and Flow Diagrams

Stock and flow diagrams are widely used in epidemiology to model the dyn...
research
11/01/2022

A Categorical Framework for Modeling with Stock and Flow Diagrams

Stock and flow diagrams are already an important tool in epidemiology, b...
research
11/24/2020

Transforming Data Flow Diagrams for Privacy Compliance (Long Version)

Recent regulations, such as the European General Data Protection Regulat...
research
04/06/2022

Fluently specifying taint-flow queries with fluentTQL

Previous work has shown that taint analyses are only useful if correctly...
research
03/20/2023

A set of semantic data flow diagrams and its security analysis based on ontologies and knowledge graphs

For a long time threat modeling was treated as a manual, complicated pro...
research
05/03/2023

Hierarchical and Upstream-Downstream Composition of Stock and Flow Models

The growing complexity of decision-making in public health and health ca...

Please sign up or login with your details

Forgot password? Click here to reset