Methods and models for identifying threats at the design stage of information systems
This article examines cybersecurity issues that affect the efficient and fully functional operation of information systems which have rapidly integrated into human activities today. It analyzes approaches to identifying and eliminating cybersecurity threats not only during the creation of information systems but also at the stage of their architecture formation. The application of STRIDE, CWE, and OWASP methodologies and their shortcomings are highlighted. It should be noted that a comprehensive analysis and description of the information system`s services in threat modeling leads to the maximum formalization of potential threats. It is known that the software development lifecycle is recognized as a standard for all programmers. However, cybersecurity experts acknowledge that even in this scheme, there are insufficient stages that account for all cybersecurity threats. To address this, it is proposed to identify cybersecurity threats at the initial stages and define measures to eliminate them by introducing additional processes into the lifecycle of SDLC information system development. In this regard, it is important to develop a metamodel of information system elements and formalize the forms of activity.
[1] Microsoft, the STRIDE Threat Model, Microsoft Corporation, 2009.
[2] MITRE Corporation, Common attack pattern enumeration and classification (capec), 2018, http://capec.mitre.org/.
[3] MITRE Corporation, Common weakness enumeration (cwe), 2018, https://cwe.mitre.org/.
[4] A. Shostack, Threat Modeling: Designing for Security, John Wiley & Sons, 2014.
[5] T. UcedaV?lez, M.M. Morana, Risk Centric Threat Modeling: Process for Attack Simulation and Threat Analysis, first ed., John Wiley & Sons, 2015.
[6] B. Selic, The pragmatics of model-driven development, IEEE Softw. 20 (5) (2003) 19–25.
[7] J. Jensen, M.G. Jaatun, Security in model driven development: A survey, in: Proceedings of the 2011 Sixth International Conference on Availability, Reliability and Security. ARES ’11, IEEE Computer Society, 2011, pp. 704–709.
[8] L. Lucio, Q. Zhang, P.H. Nguyen, M. Amrani, J. Klein, H. Vangheluwe, Y.L. Traon, Advances in model-driven security, Adv. Comput. 93 (2014) 103–152.
[9] S. Hussain, H. Erwin, P. Dunne, Threat modeling using formal methods: A new approach to develop secure web applications, in: Proceedigns of the 7th International Conference on Emerging Technologies, 2011, pp. 1–5.
[10] A. Mana, G. Pujol, Towards formal specification of abstract security properties, in: Proceedings of the Third International Conference on Availability, Reliability and Security, 2008, pp. 80–87.
[1] Y. Bertot, P. Cast?ran, Interactive Theorem Proving and Program Development: Coq’Art: The Calculus of Inductive Constructions, in: Texts in Theoretical Computer Science An EATCS Series, Springer Berlin/Heidelberg, 2004.
[11] OMG, Object constraint language (OCL), version 2.2, 2010, http://www.omg.org/spec/OCL/2.2
[12] D. Sgandurra, E. Karafili, E. Lupu, Formalizing threat models for virtualized systems, in: S. Ranise, V. Swarup (Eds.), Proceedings of Data and Applications Security and Privacy XXX, in: Lecture Notes in Computer Science, vol. 9766, Springer International Publishing, 2016, pp. 251–267.
[13] OWASP, Application threat modeling, 2017, https://www.owasp.org/index.php/ Application_Threat_Modeling.