Visible to the public Knowledge-enriched Security and Privacy Threat Modeling

TitleKnowledge-enriched Security and Privacy Threat Modeling
Publication TypeConference Paper
Year of Publication2018
AuthorsSion, Laurens, Yskout, Koen, Van Landuyt, Dimitri, Joosen, Wouter
Conference NameProceedings of the 40th International Conference on Software Engineering: Companion Proceeedings
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-5663-3
KeywordsDesign, Human Behavior, metric, model enrichment, pubcrawl, Resiliency, security, threat mitigation, threat modeling
AbstractCreating secure and privacy-protecting systems entails the simultaneous coordination of development activities along three different yet mutually influencing dimensions: translating (security and privacy) goals to design choices, analyzing the design for threats, and performing a risk analysis of these threats in light of the goals. These activities are often executed in isolation, and such a disconnect impedes the prioritization of elicited threats, assessment which threats are sufficiently mitigated, and decision-making in terms of which risks can be accepted. In the proposed TMaRA approach, we facilitate the simultaneous consideration of these dimensions by integrating support for threat modeling, risk analysis, and design decisions. Key risk assessment inputs are systematically modeled and threat modeling efforts are fed back into the risk management process. This enables prioritizing threats based on their estimated risk, thereby providing decision support in the mitigation, acceptance, or transferral of risk for the system under design.
URLhttp://doi.acm.org/10.1145/3183440.3194975
DOI10.1145/3183440.3194975
Citation Keysion_knowledge-enriched_2018