Title
Regression Nodes: Extending attack trees with data from social sciences
Abstract
In the field of security, attack trees are often used to assess security vulnerabilities probabilistically in relation to multi-step attacks. The nodes are usually connected via AND-gates, where all children must be executed, or via OR-gates, where only one action is necessary for the attack step to succeed. This logic, however, is not suitable for including human interaction such as that of social engineering, because the attacker may combine different persuasion principles to different degrees, with different associated success probabilities. Experimental results in this domain are typically represented by regression equations rather than logical gates. This paper therefore proposes an extension to attack trees involving a regression-node, illustrated by data obtained from a social engineering experiment. By allowing the annotation of leaf nodes with experimental data from social science, the regression-node enables the development of integrated socio-technical security models.
Year
DOI
Venue
2015
10.1109/STAST.2015.11
STAST
Keywords
Field
DocType
regression nodes,attack trees,social sciences,security vulnerabilities,multistep attacks,AND-gates,OR-gates,human interaction,social engineering,regression equations
Social science,Logic gate,Persuasion,Annotation,Regression,Computer security,Computer science,Attack tree,Social engineering (security),Theoretical computer science,Computer security model,Vulnerability
Conference
ISSN
Citations 
PageRank 
2325-1689
0
0.34
References 
Authors
6
5
Name
Order
Citations
PageRank
Jan-Willem Bullee141.42
Lorena Montoya200.34
Wolter Pieters322628.57
Marianne Junger4145.58
Pieter Hartel51159115.28