Hier finden Sie wissenschaftliche Publikationen aus den Fraunhofer-Instituten.

Modeling and execution of complex attack scenarios using interval timed colored petri nets

: Dahl, O.M.; Wolthusen, S.


Cole, J.L.; Wolthusen, S. ; IEEE Computer Society; Institute of Electrical and Electronics Engineers -IEEE-:
Fourth IEEE International Workshop on Information Assurance 2006. Proceedings : IWIA 2006; 13-14 April 2006; Egham, Surrey, UNITED KINGDOM
Los Alamitos, Calif.: IEEE Computer Society, 2006
ISBN: 0-7695-2564-4
International Workshop on Information Assurance (IWIA) <4, 2006, Egham>
Fraunhofer IGD ()
petri net; network security; formal method; security

The commonly used flaw hypothesis model (FHM) for performing penetration tests provides only limited, high-level guidance for the derivation of actual penetration attempts. In this paper, a mechanism for the systematic modeling, simulation, and exploitation of complex multi-stage and multi-agent vulnerabilities in networked and distributed systems based on stochastic and interval-timed colored Petri nets is described and analyzed through case studies elucidating several properties of Petri net variants and their suitability to modeling this type of attack.