发明名称 Value-Adaptive Security Threat Modeling and Vulnerability Ranking
摘要 Among others, techniques and systems are disclosed for analyzing security threats associated with software and computer vulnerabilities. Stakeholder values relevant for a software system are identified. The identified stakeholder values are quantified using a quantitative decision making approach to prioritize vulnerabilities of the software system. A structured attack graph is generated to include the quantified stakeholder values to define a scalable framework to evaluate attack scenarios. The structured attack graph includes two or more nodes. Based on the generated structured attack graph, structured attack paths are identified with each attack path representing each attack scenario.
申请公布号 US2009077666(A1) 申请公布日期 2009.03.19
申请号 US20080047293 申请日期 2008.03.12
申请人 UNIVERSITY OF SOUTHERN CALIFORNIA 发明人 CHEN YUE;BOEHM BARRY W.;SHEPPARD LUKE
分类号 G06F11/32 主分类号 G06F11/32
代理机构 代理人
主权项
地址