Attack Trees are a graphical model of security used to study threat scenarios. While visually appealing and supported by solid theories and effective tools, one of their main drawbacks remains the amount of effort required by security experts to design them from scratch. This work aims to remedy this by providing a method for the automatic generation of Attack Trees from attack logs. The main original feature of our approach w.r.t existing ones is the use of Process Mining algorithms to synthesize Attack Trees, which allow users to customize the way a set of logs are summarized as an Attack Tree, for example by discarding statistically irrelevant events. Our approach is supported by a prototype that, apart from the derivation and translation of the model, provides the user with an Attack Tree in the RisQFLan format, a tool used for quantitative risk modeling and analysis with Attack Trees. We illustrate our approach with the case study of attacks on a communication protocol, produced by a state-of-the-art protocol analyzer.
翻译:攻击树是一种用于研究威胁场景的安全图形化模型。尽管其视觉直观、有坚实理论支撑且配备高效工具,但其主要缺陷之一仍是安全专家需从头设计所需的大量工作。本研究旨在通过提出一种从攻击日志自动生成攻击树的方法来解决这一难题。相较于现有方法,我们方法的核心创新在于运用过程挖掘算法合成攻击树——该算法允许用户自定义日志集汇总为攻击树的方式,例如剔除统计上无关的事件。我们通过原型系统支撑该方法,除模型推导与转换外,还能以RisQFLan格式(一种基于攻击树进行定量风险建模与分析的工具)向用户提供攻击树。我们以通信协议攻击案例研究验证该方法,攻击案例由先进的协议分析器生成。