loading
Papers Papers/2022 Papers Papers/2022

Research.Publish.Connect.

Paper

Paper Unlock

Authors: Kees Leune and Sung Kim

Affiliation: Adelphi University, 1 South Avenue, Garden City NY, U.S.A.

Keyword(s): Conceptual Modeling, Threat Modeling, Service-Oriented Architecture, Service-Oriented Computing, Conceptbase, Threat Analysis, Indicators of Compromise, IOC.

Abstract: Today’s enterprise environment is rapidly changing with organizations adopting cloud services at record rates. This deperimeterization of enterprise computing architectures depends on software as a service (SaaS) and makes traditional perimeter-based defense controls less effective. We propose a service-oriented threat modeling approach that focuses on the perspective of a service consumer. We supplement our approach by providing an implementation view that includes technical details of service implementations that can be queried to identify potential vulnerabilities in the system. Our approach differs from existing threat modeling methods in that we seek to capture interactions between services in a technologically agnostic manner. This extends the applicability of our model into the realm of security operations. A case study and proof-of-concept are presented to validate our approach and demonstrate how such a model can be used to provide meaningful support for operations engineers.

CC BY-NC-ND 4.0

Sign In Guest: Register as new SciTePress user now for free.

Sign In SciTePress user: please login.

PDF ImageMy Papers

You are not signed in, therefore limits apply to your IP address 3.145.94.251

In the current month:
Recent papers: 100 available of 100 total
2+ years older papers: 200 available of 200 total

Paper citation in several formats:
Leune, K. and Kim, S. (2021). Supporting Cyber Threat Analysis with Service-Oriented Enterprise Modeling. In Proceedings of the 18th International Conference on Security and Cryptography - SECRYPT; ISBN 978-989-758-524-1; ISSN 2184-7711, SciTePress, pages 385-394. DOI: 10.5220/0010502503850394

@conference{secrypt21,
author={Kees Leune. and Sung Kim.},
title={Supporting Cyber Threat Analysis with Service-Oriented Enterprise Modeling},
booktitle={Proceedings of the 18th International Conference on Security and Cryptography - SECRYPT},
year={2021},
pages={385-394},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0010502503850394},
isbn={978-989-758-524-1},
issn={2184-7711},
}

TY - CONF

JO - Proceedings of the 18th International Conference on Security and Cryptography - SECRYPT
TI - Supporting Cyber Threat Analysis with Service-Oriented Enterprise Modeling
SN - 978-989-758-524-1
IS - 2184-7711
AU - Leune, K.
AU - Kim, S.
PY - 2021
SP - 385
EP - 394
DO - 10.5220/0010502503850394
PB - SciTePress