Evaluating the Implications of Attack and Security Patterns with Premortems.
This data was imported from Scopus:
Authors: Faily, S., Parkin, S. and Lyle, J.
© 2014 Springer International Publishing Switzerland. All rights are reserved. Security patterns are a useful way of describing, packaging and applying security knowledge which might otherwise be unavailable. However, because patterns represent partial knowledge of a problem and solution space, there is little certainty that addressing the consequences of one problem won't introduce or exacerbate another. Rather than using patterns exclusively to explore possible solutions to security problems, we can use them to better understand the security problem space. To this end, we present a framework for evaluating the implications of security and attack patterns using premortems: scenarios describing a failed system that invites reasons for its failure. We illustrate our approach using an example from the EU FP 7 webinos project.