Supporting Cyber Threat Analysis with Service-Oriented Enterprise Modeling

被引:2
|
作者
Leune, Kees [1 ]
Kim, Sung [1 ]
机构
[1] Adelphi Univ, 1 South Ave, Garden City, NY 11530 USA
关键词
Conceptual Modeling; Threat Modeling; Service-Oriented Architecture; Service-Oriented Computing; Conceptbase; Threat Analysis; Indicators of Compromise; IOC;
D O I
10.5220/0010502503850394
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Today's enterprise environment is rapidly changing with organizations adopting cloud services at record rates. This deperimeterization of enterprise computing architectures depends on software as a service (SaaS) and makes traditional perimeter-based defense controls less effective. We propose a service-oriented threat modeling approach that focuses on the perspective of a service consumer. We supplement our approach by providing an implementation view that includes technical details of service implementations that can be queried to identify potential vulnerabilities in the system. Our approach differs from existing threat modeling methods in that we seek to capture interactions between services in a technologically agnostic manner. This extends the applicability of our model into the realm of security operations. A case study and proof-of-concept are presented to validate our approach and demonstrate how such a model can be used to provide meaningful support for operations engineers.
引用
收藏
页码:385 / 394
页数:10
相关论文
共 50 条
  • [41] Modelling organic adaptable service-oriented enterprise architectures
    Ribeiro-Justo, GR
    Karran, T
    ON THE MOVE TO MEANINGFUL INTERNET SYSTEMS 2003: OTM 2003 WORKSHOPS, 2003, 2889 : 123 - 136
  • [42] Quasar Enterprise: Service-oriented designing of application landscapes
    Engels, Gregor
    Voß, Markus
    Informatik-Spektrum, 2008, 31 (06) : 548 - 555
  • [43] Usability Challenges for Enterprise Service-Oriented Architecture APIs
    Beaton, Jack
    Jeong, Sac Young
    Xie, Yingyu
    Stylos, Jeffrey
    Myers, Brad A.
    2008 IEEE SYMPOSIUM ON VISUAL LANGUAGES AND HUMAN-CENTRIC COMPUTING, PROCEEDINGS, 2008, : 193 - 196
  • [44] Enterprise integration platform based on service-oriented architecture
    Meng Xiaojun
    Zhang Xu
    Ning Ruxin
    Song Yu
    CHINESE JOURNAL OF MECHANICAL ENGINEERING, 2008, 21 (03) : 36 - 40
  • [45] Modeling and design of service-oriented architecture
    Stojanovic, Z
    Dahanayake, A
    Sol, H
    2004 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN & CYBERNETICS, VOLS 1-7, 2004, : 4147 - 4152
  • [46] Searching and Finding Concepts in Service-Oriented Enterprise Software
    Panchenko, Oleksandr
    Zeier, Alexander
    2008 IEEE SYMPOSIUM ON ADVANCED MANAGEMENT OF INFORMATION FOR GLOBALIZED ENTERPRISES, PROCEEDINGS, 2008, : 166 - 170
  • [47] Studying the Documentation of an API for Enterprise Service-Oriented Architecture
    Myers, Brad A.
    Jeong, Sae Young
    Xie, Yingyu
    Beaton, Jack
    Stylos, Jeff
    Ehret, Ralf
    Karstens, Jan
    Efeoglu, Arkin
    Busse, Daniela K.
    JOURNAL OF ORGANIZATIONAL AND END USER COMPUTING, 2010, 22 (01) : 23 - 51
  • [48] Service-Oriented Architecture for deploying and integrating enterprise applications
    Jiang, Michael
    Willey, Allan
    5TH WORKING IEEE/IFIP CONFERENCE ON SOFTWARE ARCHITECTURE, PROCEEDINGS, 2006, : 272 - +
  • [49] Securing Enterprise Applications: Service-Oriented Security (SOS)
    Farkas, Csilla
    Huhns, Michael N.
    IEEE JOINT CONFERENCE ON E-COMMERCE TECHNOLOGY (CEC'08) AND ENTERPRISE COMPUTING, E-COMMERCE AND E-SERVICES (EEE'08), 2008, : 428 - 431
  • [50] Calculating the business importance of entities in a service-oriented enterprise
    Fisher, Amit
    Fournier, Fabiana
    Gilat, Dagan
    Rackham, Guy
    Razinkov, Natalia
    Wasserkrug, Segev
    2007 IEEE INTERNATIONAL CONFERENCE ON SERVICES COMPUTING, PROCEEDINGS, 2007, : 717 - +