The analysis approach of ThreatGet

07/21/2021
by   Korbinian Christl, et al.
0

Nowadays, almost all electronic devices include a communication interface that allows to interact with them, exchange data, or operate their services remotely. The trend toward increased interconnectivity simultaneously increases the vulnerability of these systems. Due to the high costs associated with comprehensive security analysis, many manufacturers neglect the safety aspect of a product in order to avoid costs. However, the importance of secure IT systems is growing, as the security of a system can also influence safety-critical aspects. Standard security analysis approaches are nowadays still mainly based on time-intensive and error-prone manual activities. In this paper, we present the formal concepts of the automatic threat and vulnerability analysis tool ThreatGet. Therefore, we introduce the concept of the Extended Data-Flow Diagram that is used to represent the system under investigation in an abstracted form, and we highlight the formal analysis language of the tool. This domain-specific language is used to formulate so-called anti-patterns. These anti-patterns that can be interpreted by the tool for an automatic security analysis of the system. Besides the language declaration, we present the entire semantic evaluation of the language during the analysis. Parts of the definitions and elaborations of the diagram model and the analysis language were developed in the context of the master thesis of Korbinian Christl, in cooperation with the University of Vienna.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
03/20/2023

A set of semantic data flow diagrams and its security analysis based on ontologies and knowledge graphs

For a long time threat modeling was treated as a manual, complicated pro...
research
11/08/2021

Development of a Meta-language and its Qualifiable Implementation for the Use in Safety-critical Software

The use of domain-specific modeling for development of complex (cyber-ph...
research
01/25/2022

Automating Safety and Security Co-Design through Semantically-Rich Architecture Patterns

During the design of safety-critical systems, safety and security engine...
research
09/03/2020

Exploratory Analysis of File System Metadata for Rapid Investigation of Security Incidents

Investigating cybersecurity incidents requires in-depth knowledge from t...
research
08/09/2021

A Concept for a Qualifiable (Meta)-Modeling Framework Deployable in Systems and Tools of Safety-critical and Cyber-physical Environments

The development of cyber-physical systems can significantly benefit from...
research
09/06/2019

Data Driven Vulnerability Exploration for Design Phase System Analysis

Applying security as a lifecycle practice is becoming increasingly impor...
research
08/14/2019

Network Reconnaissance and Vulnerability Excavation of Secure DDS Systems

Distribution Service (DDS) is a realtime peer-to-peer protocol that serv...

Please sign up or login with your details

Forgot password? Click here to reset