用形式化推理自动识别系统设计中的漏洞并管理安全控制。
Automated Reasoning for Vulnerability Management by Design
- 基于形式化方法构建自动化推理机制,支持系统性漏洞分析。
- 可在真实案例中识别适用漏洞并指定缓解措施,提升设计安全性。
- 适合系统安全设计者使用,尤其关注主动防御与可控性。
为保障系统安全,必须管理其漏洞状态并设计合适的防护措施。漏洞管理可通过在系统设计中融入相关安全控制来主动应对漏洞。当前的漏洞管理方法缺乏对系统设计漏洞态势的系统性推理支持。为此,我们提出一种形式化基础的自动化推理机制,并将其集成到开源安全设计工具中,通过一个基于真实挑战的示例展示其应用。该机制使系统设计师能够识别适用于特定设计的漏洞,明确指定漏洞缓解选项,声明所选控制措施,从而实现对漏洞态势的系统化管理。
原文摘要 · Abstract (English)
For securing systems, it is essential to manage their vulnerability posture and design appropriate security controls. Vulnerability management allows to proactively address vulnerabilities by incorporating pertinent security controls into systems designs. Current vulnerability management approaches do not support systematic reasoning about the vulnerability postures of systems designs. To effectively manage vulnerabilities and design security controls, we propose a formally grounded automated reasoning mechanism. We integrate the mechanism into an open-source security design tool and demonstrate its application through an illustrative example driven by real-world challenges. The automated reasoning mechanism allows system designers to identify vulnerabilities that are applicable to a specific system design, explicitly specify vulnerability mitigation options, declare selected controls, and thus systematically manage vulnerability postures.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。