Authors
Igor Kotenko, Andrey Chechulin
Publication date
2012/12
Journal
International Transactions on Systems Science and Applications
Volume
8
Pages
129-147
Description
The paper suggests a framework for attack modeling and security evaluation in Security Information and Event Management (SIEM) systems applicable for future systems of the Internet of Things. It is supposed that the common approach to attack modeling and security evaluation is based on modeling of a malefactor’s behavior, generating a common attack graph, calculating different security metrics and providing risk analysis procedures. Key elements of suggested architectural solutions for attack modeling and security evaluation are using a comprehensive security repository, effective attack graph (tree) generation techniques, taking into account known and new attacks based on zero-day vulnerabilities, stochastic analytical modeling, and interactive decision support to choose preferred security solutions. The architecture of the Attack Modeling and Security Evaluation Component (AMSEC) is proposed, its …
Total citations
2012201320142015201620172018201920202021202220232024110131051616645543
Scholar articles
I Kotenko, A Chechulin - International Transactions on Systems Science and …, 2012