Conference paper ยท Book chapter
Model checking exact cost for attack scenarios
Attack trees constitute a powerful tool for modelling security threats. Many security analyses of attack trees can be seamlessly expressed as model checking of Markov Decision Processes obtained from the attack trees, thus reaping the benefits of a coherent framework and a mature tool support. However, current model checking does not encompass the exact cost analysis of an attack, which is standard for attack trees.
Our first contribution is the logic erPCTL with cost-related operators. The extended logic allows to analyse the probability of an event satisfying given cost bounds and to compute the exact cost of an event. Our second contribution is the model checking algorithm for erPCTL. Finally, we apply our framework to the analysis of attack trees.
Language: | English |
---|---|
Publisher: | Springer |
Year: | 2017 |
Pages: | 210-31 |
Proceedings: | 6<sup>th</sup> International Conference on Principles of Security and Trust<br/> |
Series: | Lecture Notes in Computer Science |
Journal subtitle: | 6th International Conference, Post 2017, Held As Part of the European Joint Conferences on Theory and Practice of Software, Etaps 2017, Uppsala, Sweden, April 22-29, 2017, Proceedings |
ISBN: | 3662544547 , 3662544555 , 9783662544549 and 9783662544556 |
ISSN: | 03029743 |
Types: | Conference paper and Book chapter |
DOI: | 10.1007/978-3-662-54455-6_10 |
ORCIDs: | Nielson, Flemming |