中文
相关论文

相关论文: URSID: Using formalism to Refine attack Scenarios …

200 篇论文

Organizations face an ever-changing threat landscape. They must continuously dedicate significant efforts to protect their assets, making their adoption of increased cybersecurity automation inevitable. However, process automation requires…

计算与语言 · 计算机科学 2025-07-18 Quentin Goux , Nadira Lammari

In this work we start walking the path to a new perspective for viewing cyberwarfare scenarios, by introducing conceptual tools (a formal model) to evaluate the costs of an attack, to describe the theater of operations, targets, missions,…

密码学与安全 · 计算机科学 2010-06-11 Ariel Futoransky , Luciano Notarfrancesco , Gerardo Richarte , Carlos Sarraute

Recently efficient model-checking tools have been developed to find flaws in security protocols specifications. These flaws can be interpreted as potential attacks scenarios but the feasability of these scenarios need to be confirmed at the…

密码学与安全 · 计算机科学 2013-08-01 Hatem Ghabri , Ghazi Maatoug , Michael Rusinowitch

Cyber-secure networked control is modeled, analyzed, and experimentally illustrated in this paper. An attack space defined by the adversary's system knowledge, disclosure, and disruption resources is introduced. Adversaries constrained by…

最优化与控制 · 数学 2012-12-04 André Teixeira , Iman Shames , Henrik Sandberg , Karl H. Johansson

Modern infrastructures rely on software systems that remain vulnerable to cyberattacks. These attacks frequently exploit vulnerabilities documented in repositories such as MITRE's Common Vulnerabilities and Exposures (CVE). However, Cyber…

密码学与安全 · 计算机科学 2026-02-27 Refat Othman

In this paper, we introduce a formal notion of partial compliance, called Attack-resistance, of a computer program running together with a defense mechanism w.r.t a non-exploitability specification. In our setting, a program may contain…

密码学与安全 · 计算机科学 2015-06-15 Vijay Ganesh , Sebastian Banescu , Martín Ochoa

Real-Time systems are essential for promptly responding to external stimuli and completing tasks within predefined time constraints. Ensuring high reliability and robust security in these systems is therefore critical. This requires…

密码学与安全 · 计算机科学 2025-10-07 Eliron Rahimi , Kfir Girstein , Roman Malits , Avi Mendelson

We propose a formal treatment of scenarios in the context of a dialectical argumentation formalism for qualitative reasoning about uncertain propositions. Our formalism extends prior work in which arguments for and against uncertain…

人工智能 · 计算机科学 2013-01-07 Peter McBurney , Simon Parsons

Web applications require access to the file-system for many different tasks. When analyzing the security of a web application, secu- rity analysts should thus consider the impact that file-system operations have on the security of the whole…

密码学与安全 · 计算机科学 2017-05-11 Federico De Meo , Luca Viganò

According to the World Economic Forum, cyber attacks are considered as one of the most important sources of risk to companies and institutions worldwide. Attacks can target the network, software, and/or hardware. During the past years, much…

密码学与安全 · 计算机科学 2022-08-31 Tara Ghasempouri , Jaan Raik , Cezar Reinbrecht , Said Hamdioui , Mottaqiallah Taouil

Characterizing attacker behavior with respect to Cyber-Physical Systems is important to assuring the security posture and resilience of these systems. Classical cyber vulnerability assessment approaches rely on the knowledge and experience…

密码学与安全 · 计算机科学 2021-03-18 Christopher Deloglos , Carl Elks , Ashraf Tantawy

Securing cloud configurations is an elusive task, which is left up to system administrators who have to base their decisions on ``trial and error'' experimentations or by observing good practices (e.g., CIS Benchmarks). We propose a…

密码学与安全 · 计算机科学 2022-06-08 Francesco Minna , Fabio Massacci , Katja Tuma

This paper is a tutorial on the proven but currently under-appreciated security mechanisms associated with "tagged" or "descriptor" architectures. The tutorial shows how the principles behind such architectures can be applied to mitigate or…

密码学与安全 · 计算机科学 2025-04-24 William Earl Boebert

We introduce a new simulation platform called Insight, created to design and simulate cyber-attacks against large arbitrary target scenarios. Insight has surprisingly low hardware and configuration requirements, while making the simulation…

密码学与安全 · 计算机科学 2010-06-11 Ariel Futoransky , Fernando Miranda , Jose Orlicki , Carlos Sarraute

Cloud computing is becoming an increasingly lucrative branch of the existing information and communication technologies (ICT). Enabling a debate about cloud usage scenarios can help with attracting new customers, sharing best-practices, and…

分布式、并行与集群计算 · 计算机科学 2014-10-07 Aleksandar Milenkoski , Alexandru Iosup , Samuel Kounev , Kai Sachs , Piotr Rygielski , Jason Ding , Walfredo Cirne , Florian Rosenberg

By exploiting the increasing surface attack of systems, cyber-attacks can cause catastrophic events, such as, remotely disable safety mechanisms. This means that in order to avoid hazards, safety and security need to be integrated,…

计算机科学中的逻辑 · 计算机科学 2019-01-03 Vivek Nigam , Alexander Pretschner , Harald Ruess

Risk assessment plays a crucial role in ensuring the security and resilience of modern computer systems. Existing methods for conducting risk assessments often suffer from tedious and time-consuming processes, making it challenging to…

密码学与安全 · 计算机科学 2023-07-27 Simon Unger , Ektor Arzoglou , Markus Heinrich , Dirk Scheuermann , Stefan Katzenbeisser

Graph models are helpful means of analyzing computer networks as well as complex system architectures for security. In this paper we evaluate the current state of research for representing and analysing cyber-attack using graph models, i.e.…

密码学与安全 · 计算机科学 2023-11-17 Jasmin Wachter

In this work we present a prototype for simulating computer network attacks. Our objective is to simulate large networks (thousands of hosts, with applications and vulnerabilities) while remaining realistic from the attacker's point of…

密码学与安全 · 计算机科学 2010-06-15 Carlos Sarraute , Fernando Miranda , Jose I. Orlicki

A cyber range is an environment used for training security experts and testing attack and defence tools and procedures. Usually, a cyber range simulates one or more critical infrastructures that attacking (red) and defending (blue) teams…

密码学与安全 · 计算机科学 2023-02-01 Gabriele Costa , Enrico Russo , Alessandro Armando
‹ 上一页 1 2 3 10 下一页 ›