Minimizing information security risks based on security threat modeling

Инна Ильинична Баранкова, U V Mikhailova, M V Afanaseva · Journal of Physics Conference Series · 2020

Abstract The well-elaborated models of information security threats (IST) allow for the optimal development of a protection plan. This plan will be based on current threats and will consider effective countermeasures that increase the level of information security (IS). The threat model is described using different automation methodologies of this process. It is also possible to visualize the structure of complex objects and processes them from the required angle and with sufficient granularity. Constructing various threat implementations as trees or attack graphs (AG) is one of the relevant directions in assessing the level of IS. The creation of a software application for automation and formalization of assessing the information security process of IS assets, and the localization of bottlenecks in the IS protection, is dealt with in the article. A distinctive feature of the application is the use of the Federal Service for Technology and Export Control of Russia (FSTEC of Russia) threat data bank for modeling the attack tree. The developed software application allows you to reduce time, simplify the process of assessing the security of an IS, and also visualizes the threat modeling process. The scope of the developed software product may be small and medium-sized businesses, as well as state-owned enterprises.

Read the paper · More papers on PaperTik