The future of enterprise cyber defense is predictive and the use of model-based threat hunting is an enabling technique. Current approaches to threat modeling are predicated on the assumption that models are used to develop better software, rather than to describe threats to software being used as a service (SaaS). In this paper, we propose a service-modeling methodology that will facilitate pro-active cyber defense for organizations adopting SaaS. We model structural and dynamic elements to provide a robust representation of the defensible system. Our approach is validated by implementing a prototype and by using it to model a popular course management system.
CITATION STYLE
Leune, K., & Kim, S. (2020). Service-Oriented Modeling for Cyber Threat Analysis. In CODASPY 2020 - Proceedings of the 10th ACM Conference on Data and Application Security and Privacy (pp. 150–152). Association for Computing Machinery, Inc. https://doi.org/10.1145/3374664.3379528
Mendeley helps you to discover research relevant for your work.