Probabilistic Attack Scenarios to Evaluate Policies over Communication Protocols

Samir Ouchani, Yosr Jarraya, Otmane Aı̈t Mohamed, Mourad Debbabi · Journal of Software · 2012

Abstract — Security is an important non-functional require-ment that should be analyzed in any system or software that is potentially exposed to security threats. Since we can’t manage what we don’t measure, it is not enough to address only the qualitative assessment of security. In this paper, we propose a novel approach that leads to a qualitative and quantitative analysis of communication protocols. Our approach is based on probabilistic model-checking and probabilistic attack scenarios. To the best of our knowledge, the present work is the first initiative that combines these two techniques in the verification of security of communication protocol. Considering that security attacks are random in nature, we quantify this randomness using probability values denoting the likelihoods of attacks to occur. The composed model formed by the attack scenario and the system model is then analyzed using the probabilistic model-checker PRISM against a set of security and performance requirements. As a case study, we demonstrated the applicability of our approach on Secure Real-time Transport Protocol over Real-Time Streaming Protocol (RTSP/SRTP).

Read the paper · More papers on PaperTik