Abstract : Attack trees are a popular way to represent and evaluate potential security threats on systems or infrastructures. The goal of this work is to provide a framework allowing to express and check whether an attack tree is consistent with the analyzed system. We model real systems using transition systems and introduce attack trees with formally specified node labels. We formulate the cor-rectness properties of an attack tree with respect to a system and study the complexity of the corresponding decision problems. The proposed framework can be used in practice to assist security experts in manual creation of attack trees and enhance development of tools for automated generation of attack trees.
https://hal.inria.fr/hal-01686505 Contributor : Maxime AudinotConnect in order to contact the contributor Submitted on : Wednesday, January 17, 2018 - 2:43:27 PM Last modification on : Wednesday, November 3, 2021 - 6:03:42 AM Long-term archiving on: : Sunday, May 6, 2018 - 5:35:20 AM
Maxime Audinot, Sophie Pinchinat, Barbara Kordy. Is my attack tree correct?. ESORICS 2017 - 22nd European Symposium on Research in Computer Security, Sep 2017, Oslo, Norway. pp.83-102, ⟨10.1007/978-3-319-66402-6_7⟩. ⟨hal-01686505⟩