Supporting Cyber Threat Analysis with Service-Oriented Enterprise Modeling

被引:2
|
作者
Leune, Kees [1 ]
Kim, Sung [1 ]
机构
[1] Adelphi Univ, 1 South Ave, Garden City, NY 11530 USA
关键词
Conceptual Modeling; Threat Modeling; Service-Oriented Architecture; Service-Oriented Computing; Conceptbase; Threat Analysis; Indicators of Compromise; IOC;
D O I
10.5220/0010502503850394
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Today's enterprise environment is rapidly changing with organizations adopting cloud services at record rates. This deperimeterization of enterprise computing architectures depends on software as a service (SaaS) and makes traditional perimeter-based defense controls less effective. We propose a service-oriented threat modeling approach that focuses on the perspective of a service consumer. We supplement our approach by providing an implementation view that includes technical details of service implementations that can be queried to identify potential vulnerabilities in the system. Our approach differs from existing threat modeling methods in that we seek to capture interactions between services in a technologically agnostic manner. This extends the applicability of our model into the realm of security operations. A case study and proof-of-concept are presented to validate our approach and demonstrate how such a model can be used to provide meaningful support for operations engineers.
引用
收藏
页码:385 / 394
页数:10
相关论文
共 50 条
  • [1] Service-Oriented Modeling for Cyber Threat Analysis
    Leune, Kees
    Kim, Sung
    PROCEEDINGS OF THE TENTH ACM CONFERENCE ON DATA AND APPLICATION SECURITY AND PRIVACY, CODASPY 2020, 2020, : 150 - 152
  • [2] Business Service Modeling for the Service-Oriented Enterprise
    Arachchige, Jeewanie Jayasinghe
    Weigand, Hans
    Jeusfeld, Manfred
    INTERNATIONAL JOURNAL OF INFORMATION SYSTEM MODELING AND DESIGN, 2012, 3 (01) : 1 - 22
  • [3] Modeling enterprise service-oriented architectural styles
    Tang, Longji
    Dong, Jing
    Peng, Tu
    Tsai, Wei-Tek
    SERVICE ORIENTED COMPUTING AND APPLICATIONS, 2010, 4 (02) : 81 - 107
  • [4] The Analysis of the Policies on Service Innovation in Service-Oriented Enterprise
    Zhang Shaojun
    PROCEEDINGS OF THE 9TH INTERNATIONAL CONFERENCE ON INNOVATION AND MANAGEMENT, 2012, : 1016 - 1019
  • [5] Service-Oriented Enterprise Cooperation: Modeling Method and System
    Lin, Huiping
    Liu, Sheng
    Fan, Yushun
    2008 IEEE ASIA-PACIFIC SERVICES COMPUTING CONFERENCE, VOLS 1-3, PROCEEDINGS, 2008, : 1032 - +
  • [6] Service-Oriented Enterprise Network Performance Analysis
    曾森
    黄双喜
    范玉顺
    Tsinghua Science and Technology, 2009, 14 (04) : 492 - 503
  • [7] Service-oriented extensible modeling and simulation supporting environment research
    Xu, LJ
    Peng, XY
    Li, N
    SYSTEM SIMULATION AND SCIENTIFIC COMPUTING, VOLS 1 AND 2, PROCEEDINGS, 2005, : 665 - 669
  • [8] Modeling and analysis of service interactions in service-oriented software
    Lee, WJ
    COMPUTER AND INFORMATION SCIENCES - ISCIS 2003, 2003, 2869 : 1043 - 1050
  • [9] Service-Oriented Enterprise Interoperability in Logistics
    Hofman, Wout
    ENTERPRISE INTEROPERABILITY: RESEARCH AND APPLICATIONS IN THE SERVICE-ORIENTED ECOSYSTEM, 2013, : 185 - 198
  • [10] Transition to Service-Oriented Enterprise Architecture
    Assmann, Martin
    Engels, Gregor
    SOFTWARE ARCHITECTURE, 2008, 5292 : 346 - +