Skip to Main content Skip to Navigation
Conference papers

Towards Synthesis of Attack Trees for Supporting Computer-Aided Risk Analysis

Sophie Pinchinat 1 Mathieu Acher 2 Didier Vojtisek 2
1 LogicA - Logic and Applications
IRISA-D4 - LANGAGE ET GÉNIE LOGICIEL, UR1 - Université de Rennes 1, ENS Cachan - École normale supérieure - Cachan
2 DiverSe - Diversity-centric Software Engineering
Inria Rennes – Bretagne Atlantique , IRISA-D4 - LANGAGE ET GÉNIE LOGICIEL
Abstract : Attack trees are widely used in the fields of defense for the analysis of risks (or threats) against electronics systems, computer control systems or physical systems. Based on the analysis of attack trees, practitioners can define actions to engage in order to reduce or annihilate risks. A major barrier to support computer-aided risk analysis is that attack trees can become largely complex and thus hard to specify. This paper is a first step towards a methodology, formal foundations as well as automated techniques to synthesize attack trees from a high-level description of a system. Attacks are expressed as a succession of elementary actions and high-level actions can be used to abstract and organize attacks into exploitable attack trees. We describe our tooling support and identify open challenges for supporting the analysis of risks.
Document type :
Conference papers
Complete list of metadata

Cited literature [16 references]  Display  Hide  Download
Contributor : Mathieu Acher Connect in order to contact the contributor
Submitted on : Tuesday, September 16, 2014 - 5:10:09 PM
Last modification on : Thursday, January 20, 2022 - 5:33:17 PM
Long-term archiving on: : Wednesday, December 17, 2014 - 11:41:42 AM


Files produced by the author(s)


  • HAL Id : hal-01064645, version 1


Sophie Pinchinat, Mathieu Acher, Didier Vojtisek. Towards Synthesis of Attack Trees for Supporting Computer-Aided Risk Analysis. Workshop on Formal Methods in the Development of Software (co-located with SEFM), Sep 2014, Grenoble, France. ⟨hal-01064645⟩



Les métriques sont temporairement indisponibles