Model-based security analysis in seven steps --- a guided tour to the CORAS method

  • Authors:
  • F. Braber;I. Hogganvik;M. S. Lund;K. Stølen;F. Vraalsen

  • Affiliations:
  • -;-;-;-;-

  • Venue:
  • BT Technology Journal
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper presents the CORAS method for model-based security analysis. The presentation is case-driven. We follow two analysts in their interaction with an organisation by which they have been hired to carry out a security risk analysis. The analysis is divided into seven main steps, and the paper devotes a separate section to each of them. The paper focuses in particular on the use of the CORAS security risk modelling language as a means for communication and interaction during the seven steps.