Security Protocol Testing Using Attack Trees

  • Authors:
  • Anderson Morais;Eliane Martins;Ana Cavalli;Willy Jimenez

  • Affiliations:
  • -;-;-;-

  • Venue:
  • CSE '09 Proceedings of the 2009 International Conference on Computational Science and Engineering - Volume 02
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper we present an attack injectionapproach for security protocol testing aiming atvulnerability detection. We use attack tree model todescribe known attacks and derive injection testscenarios to test the security properties of the protocolunder evaluation. The test scenarios are converted to aspecific fault injector script after performing sometransformations. The attacker is emulated using a faultinjector. This model based approach facilitates thereusability and maintainability of the generatedinjection attacks as well as the generation of faultinjectors scripts. The approach is applied to anexisting mobile security protocol. We performedexperiments with truncation and DoS attacks; resultsshow good precision and efficiency in the injectionmethod.