Evaluating the implications of attack and security patterns with premortems

Authors: Faily, S., Parkin, S. and Lyle, J.

Volume: 9783319044477

Pages: 199-209

ISBN: 9783319044460

DOI: 10.1007/978-3-319-04447-7_16

Abstract:

Security patterns are a useful way of describing, packaging and applying security knowledge which might otherwise be unavailable. However, because patterns represent partial knowledge of a problem and solution space, there is little certainty that addressing the consequences of one problem won't introduce or exacerbate another. Rather than using patterns exclusively to explore possible solutions to security problems, we can use them to better understand the security problem space. To this end, we present a framework for evaluating the implications of security and attack patterns using premortems: scenarios describing a failed system that invites reasons for its failure. We illustrate our approach using an example from the EU FP 7 webinos project.

Source: Scopus

Evaluating the Implications of Attack and Security Patterns with Premortems

Authors: Faily, S.

Editors: Blackwell, C. and Zhu, H.

Publisher: Springer

ISBN: 978-3-319-04446-0

Source: Manual

Evaluating the Implications of Attack and Security Patterns with Premortems.

Authors: Faily, S., Parkin, S. and Lyle, J.

Editors: Blackwell, C. and Zhu, H.

Pages: 199-209

Publisher: Springer

ISBN: 978-3-319-04446-0

https://doi.org/10.1007/978-3-319-04447-7

Source: DBLP