Outline for June 3, 2013
Reading
: [TL00] (This is available in the Resources area of SmartSite; look in the folder “Handouts”)
Due
: Homework #5, due June 6, 2013
Evaluating systems
System Security Engineering Capability Maturity Model (SSE-CMM)
Attack trees
Goals and subgoals
Example: safe cracking
Different functions of nodes and edges
Risk analysis
Feasibility analysis
Cost analysis
Example: attacking PGP
Requires/provides model
Give intuition
Single exploit
vs.
scenario attacks
Correlation problem
Example:
rsh
connection spoofing
Capabilities and concepts
Some features of the model
JIGSAW language overview
You can also obtain a PDF version of this.
Version of June 2, 2013 at 8:39AM