Authors
Igor Kotenko, Mikhail Stepashkin, Elena Doynikova
Publication date
2011/2/9
Conference
2011 19th International Euromicro Conference on Parallel, Distributed and Network-Based Processing
Pages
611-618
Publisher
IEEE
Description
The paper suggests an attack trees based approach to security analysis of information systems. The approach considers both software-technical and social engineering attacks. It extends the approach to network security analysis based on software-technical attacks which was suggested earlier by the authors of this paper. The main difference is in generalizing the suggested approach for information systems and in use of different conceptions, models and frameworks related to social-engineering attacks. In particular, we define conceptions of legitimate users and control areas. Besides, social-engineering attacks and attacks that require physical access to control areas are included to the attack trees used for security analysis. The paper also describes a security analysis toolkit based on the approach suggested and experiments with it to define the security level of information system.
Total citations
2011201220132014201520162017201820192020202120222023202431196510148102822
Scholar articles
I Kotenko, M Stepashkin, E Doynikova - 2011 19th International Euromicro Conference on …, 2011