| Zugriffsnummer | 39068 |
| Dokumenttyp | Konferenzartikel in Zeitschrift |
| Peer Review | mit Peer Review |
| Sprache | Englisch |
| Titel | Representation of attacker motivation in software risk assessment using attack probability trees |
| Autor(in); Institution |
Esche, Marko; 8.5, Metrologische Informationstechnik, PTB-Berlin
Grasso Toro, Federico; 8.5, Metrologische Informationstechnik, PTB-Berlin
Thiel, Florian; 8.5, Metrologische Informationstechnik, PTB-Berlin
|
| Quelle/Jahr | Position Papers of the 2017 Federated Conference on Computer Science and Information Systems. Annals of Computer Science and Information Systems: 11 (2017), 763 - 771 |
| ISSN | 2300-5963 |
| ISBN | 978-83-946253-7-5 (online) ; 978-83-946253-8-2 (USB) |
| DOI | |
| Verlag | Warsaw: Polish Information Processing Society |
| Konferenzangaben | Federated Conference on Computer Science and Information Systems (FedCSIS), Prague, 3-6, September, 2017, Czech Republic |
| Freie Schlagworte | Software Risk Assessment ; Legal Metrology ; Attack Probability Trees ; Attacker Motivation ; Countermeasures |
| Zusammenfassung | Since software plays an ever more important role in measuring instruments, risk assessments for such instruments required by European regulations will usually include also a risk assessment of the software. Although previously introduced methods still lack efficient means for the representation of attacker motivation and have no prescribed way of constructing attack scenarios, attack trees have been used for several years in similar application scenarios. These trees are here developed into attack probability trees, specifically tailored to meet the requirements for software risk assessment. A real-world example based on taximeters is given to illustrate the application of attack probability trees approach and their advantages. |
| Kostenfreier Zugang | Open Access Gold |