Loading...

Measuring software security using SAN models

Nogoorani, S. D ; Sharif University of Technology | 2012

983 Viewed
  1. Type of Document: Article
  2. DOI: 10.1109/ISCISC.2012.6408195
  3. Publisher: 2012
  4. Abstract:
  5. Security is one of the important issues in developing and implementing software systems especially in highly critical applications. Quantification and measurement of security is one of the approaches adopted to achieve the desired degree of security. In this paper, Stochastic Activity Networks (SANs) are used to formally model the attacks on the system under investigation. To this end, the semi-Markov attack model is sketched. Having the semi-Markov model, Probability of Attack Success (PAS), Mean Time to First Breach (MTFB), and System Misuse Proportion (SMP) are measured according to the appropriate transformation of the model to a SAN model. As a case study, we have studied a high-level attack on a password authentication subsystem. The results prove the applicability and suitability of our proposed method in making the compromise between security and other system requirements
  6. Keywords:
  7. Attack model ; Critical applications ; Password authentication ; Probability of attack ; SAN models ; Security measurement ; security quantification ; Semi Markov model ; Semi-Markov ; Software security ; Software systems ; Stochastic activity networks ; System requirements ; Cryptography ; Hierarchical systems ; Markov processes ; Security of data ; Authentication
  8. Source: 2012 9th International ISC Conference on Information Security and Cryptology, ISCISC 2012, 13 September 2012 through 14 September 2012 ; September , 2012 , Pages 80-86 ; 9781467323864 (ISBN)
  9. URL: http://ieeexplore.ieee.org/xpl/articleDetails.jsp?arnumber=6408195