Architecture-Based Attack Path Analysis for Identifying Potential Security Incidents

Walter, Maximilian ORCID iD icon 1; Heinrich, Robert 1; Reussner, Ralf 1
1 Institut für Informationssicherheit und Verlässlichkeit (KASTEL), Karlsruher Institut für Technologie (KIT)


Manually estimating an attack path to a targeted software element can be complex since a software system consists of multiple vulnerable elements, such as components, hardware resources, or network elements. In addition, the elements are protected by access control. Software architecture describes the structural elements of the system, which may form elements of the attack path. However, estimating attack paths is complex since different attack paths can lead to a targeted element. Additionally, not all attack paths might be relevant since attack paths can have different properties based on the attacker's capabilities and knowledge. We developed an approach that enables architects to identify relevant attack paths based on the software architecture.
We created a metamodel for filtering options and added support for describing attack paths in an architectural description language. Based on this metamodel, we developed an analysis that automatically estimates attack paths using the software architecture. This can help architects to identify relevant attack paths to a targeted component and increase the system's overall security. ... mehr

Preprint §
DOI: 10.5445/IR/1000162061
Veröffentlicht am 13.09.2023
DOI: 10.1007/978-3-031-42592-9_3
Zitationen: 2
Zugehörige Institution(en) am KIT Institut für Informationssicherheit und Verlässlichkeit (KASTEL)
Institut für Programmstrukturen und Datenorganisation (IPD)
Publikationstyp Proceedingsbeitrag
Publikationsjahr 2023
Sprache Englisch
Identifikator ISBN: 978-3-031-42592-9
ISSN: 0302-9743
KITopen-ID: 1000162061
HGF-Programm 46.23.03 (POF IV, LK 01) Engineering Security for Mobility Systems
Erschienen in Software Architecture. Ed.: B. Tekinerdogan
Veranstaltung 17th European Conference on Software Architecture (ECSA 2023), Istanbul, Türkei, 18.09.2023 – 22.09.2023
Verlag Springer Nature Switzerland
Seiten 37–53
Serie Lecture Notes in Computer Science ; 14212
Projektinformation ANYMOS (BMBF, 16KISA086)
Vorab online veröffentlicht am 08.09.2023
