Crowd Sourcing the Creation of Personae Non Gratae for Requirements-Phase Threat Modeling

2017 IEEE 25th International Requirements Engineering Conference (RE)(2017)

引用 9|浏览17
暂无评分
摘要
Security threats should be identified in the early phases of a project so that design solutions can be explored and mitigating requirements specified. In this paper, we present a crowd-sourcing approach for creating Personae non Gratae (PnGs), which model attack goals and techniques of unwanted, potentially malicious users. We present a proof of concept study that takes a diverse collection of potentially redundant PnGs and merges them into a single set. Our approach combines machine learning techniques and visualization. It is illustrated and evaluated using a collection of PnGs collected from undergraduate students for a drone-based rescue scenario. Lessons learned from the proof of concept study are discussed and lay the foundations for future work.
更多
查看译文
关键词
Threat Modeling,Security Requirements,Personae non gratae
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要