Attack Countermeasure Tree (ACT) meets with the Split-protocol
نویسنده
چکیده
In this paper, we present a novel attack tree paradigm called attack countermeasure tree (ACT) comprising an additional attack resistant element known as the Split-protocol. ACT which circumvent the fabrication and way out of a state-space representation and takes keen on account attack, as well as countermesures (in the form of detection and mitigation events). Split-protocol as an attack resistant element enhances the availability of the system during or after a security attack on the system. We compare ACT with or without Split-protocol implantation. The split-protocol concept stemmed from splitting the HTTP/TCP protocol in webserver application. An HTTP/TCP protocol is standard on a webserver can be split into two segments, and each part can be separately run on a different Web server, thus constituting dual servers. These servers communicate across a network by using inter-server messages or delegate messages.In ACT, recognition and alleviation are allowed not just at the leaf node but also at the intermediate nodes,andsimultaneouslythe state-space explosion problem is avoided in its analysis. We study the consequences of incorporating countermeasures in the ACT and Split-protocol using various case studies.
منابع مشابه
Attack countermeasure trees (ACT): towards unifying the constructs of attack and defense trees
Attack tree (AT) is one of the widely used non-state-space models for security analysis. The basic formalism of AT does not take into account defense mechanisms. Defense trees (DTs) have been developed to investigate the effect of defense mechanisms using measures such as attack cost, security investment cost, return on attack (ROA) and return on investment (ROI). DT, however, places defense me...
متن کاملA particle swarm optimization algorithm for minimization analysis of cost-sensitive attack graphs
To prevent an exploit, the security analyst must implement a suitable countermeasure. In this paper, we consider cost-sensitive attack graphs (CAGs) for network vulnerability analysis. In these attack graphs, a weight is assigned to each countermeasure to represent the cost of its implementation. There may be multiple countermeasures with different weights for preventing a single exploit. Also,...
متن کاملLow Cost Countermeasure at Authentication Protocol Level against Electromagnetic Side Channel Attacks on RFID Tags
Radio Frequency Identification (RFID) technology is widely spread in many security applications. Producing secured low-cost and low-power RFID tags is a challenge. The used of lightweight encryption algorithms can be an economic solution for these RFID security applications. This article proposes low cost countermeasure to secure RFID tags against Electromagnetic Side Channel Attacks (EMA). Fir...
متن کاملCryptographic Salt: A Countermeasure against Denial-of-Service Attacks
Denial-of-service (DoS) attack is one of the most malicious Internetbased attacks. Introduction of cryptographic authentication protocols into Internet environment does not help alleviate the impact of denial-of-service attacks, but rather increases the vulnerability to the attack because of the heavy computation associated with cryptographic operation. Nevertheless, many Internet security prot...
متن کاملFailure of the Point Blinding Countermeasure Against Fault Attack in Pairing-Based Cryptography
Pairings are mathematical tools that have been proven to be very useful in the construction of many cryptographic protocols. Some of these protocols are suitable for implementation on power constrained devices such as smart cards or smartphone which are subject to side channel attacks. In this paper, we analyse the efficiency of the point blinding countermeasure in pairing based cryptography ag...
متن کامل