Supporting Cyber Threat Analysis with Service-Oriented Enterprise Modeling

被引:2
|
作者
Leune, Kees [1 ]
Kim, Sung [1 ]
机构
[1] Adelphi Univ, 1 South Ave, Garden City, NY 11530 USA
关键词
Conceptual Modeling; Threat Modeling; Service-Oriented Architecture; Service-Oriented Computing; Conceptbase; Threat Analysis; Indicators of Compromise; IOC;
D O I
10.5220/0010502503850394
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Today's enterprise environment is rapidly changing with organizations adopting cloud services at record rates. This deperimeterization of enterprise computing architectures depends on software as a service (SaaS) and makes traditional perimeter-based defense controls less effective. We propose a service-oriented threat modeling approach that focuses on the perspective of a service consumer. We supplement our approach by providing an implementation view that includes technical details of service implementations that can be queried to identify potential vulnerabilities in the system. Our approach differs from existing threat modeling methods in that we seek to capture interactions between services in a technologically agnostic manner. This extends the applicability of our model into the realm of security operations. A case study and proof-of-concept are presented to validate our approach and demonstrate how such a model can be used to provide meaningful support for operations engineers.
引用
收藏
页码:385 / 394
页数:10
相关论文
共 50 条
  • [31] A Service-oriented User Interaction Analysis Framework Supporting Adaptive Applications
    Hashemi, Mohammad
    Herbert, John
    PROCEEDINGS 2016 IEEE 40TH ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE WORKSHOPS (COMPSAC), VOL 2, 2016, : 546 - 551
  • [32] Aligning Service Level Agreements with Service-Oriented Enterprise Architecture
    Trung-Viet Nguyen
    Lam-Son Le
    Khuong Nguyen-An
    Thai-Minh Truong
    PROCEEDINGS OF THE 2017 IEEE 21ST INTERNATIONAL ENTERPRISE DISTRIBUTED OBJECT COMPUTING CONFERENCE WORKSHOPS AND DEMONSTRATIONS (EDOCW 2017), 2017, : 8 - 14
  • [33] Exploring enterprise service bus in the service-oriented architecture paradigm
    Indian Institute of Technology Indore, India
    不详
    不详
    不详
    Explor. Enterp. Serv. Bus in the Serv.-Oriented Archit. Paradig., 1600, (1-378):
  • [34] Business Service Modeling in Service-Oriented Enterprises
    Minaei-Bidgoli, Behrouz
    Rafati, Laleh
    NCM 2008: 4TH INTERNATIONAL CONFERENCE ON NETWORKED COMPUTING AND ADVANCED INFORMATION MANAGEMENT, VOL 2, PROCEEDINGS, 2008, : 296 - 301
  • [35] MODELING SERVICE SYSTEMS IN SERVICE-ORIENTED ENVIRONMENTS
    Adamopoulos, Dionisis X.
    WEBIST 2009: PROCEEDINGS OF THE FIFTH INTERNATIONAL CONFERENCE ON WEB INFORMATION SYSTEMS AND TECHNOLOGIES, 2009, : 85 - 88
  • [36] Adaptive Service-Oriented Architectures for Cyber Physical Systems
    Mohalik, Swarup K.
    Narendra, Nanjangud C.
    Badrinath, R.
    Duc-Hung Le
    2017 11TH IEEE SYMPOSIUM ON SERVICE-ORIENTED SYSTEM ENGINEERING (SOSE), 2017, : 57 - 62
  • [37] Service-Oriented Middleware Architectures for Cyber-Physical
    Hoang, Dat Dac
    Paik, Hye-Young
    Kim, Chae-Kyu
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2012, 12 (01): : 79 - 87
  • [38] A SERVICE-ORIENTED FRAMEWORK FOR MAS MODELING
    Yves, Wautelet
    Youssef, Achbany
    Manuel, Kolp
    ICEIS 2008: PROCEEDINGS OF THE TENTH INTERNATIONAL CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS, VOL ISAS-1: INFORMATION SYSTEMS ANALYSIS AND SPECIFICATION, VOL 1, 2008, : 120 - 128
  • [39] Modeling and refining the service-oriented requirement
    Cao Xiao-Xia
    Miao Huai-Kou
    Xu Qing-Guo
    TASE 2008: SECOND IFIP/IEEE INTERNATIONAL SYMPOSIUM ON THEORETICAL ASPECTS OF SOFTWARE ENGINEERING, PROCEEDINGS, 2008, : 159 - 165
  • [40] A modeling framework for service-oriented architecture
    Zhang, Tao
    Ying, Shi
    Cao, Sheng
    Jia, Xiangyang
    QSIC 2006: SIXTH INTERNATIONAL CONFERENCE ON QUALITY SOFTWARE, PROCEEDINGS, 2006, : 219 - +