论文标题
移动通信系统的威胁建模框架
Threat modeling framework for mobile communication systems
论文作者
论文摘要
由于移动通信系统的复杂性质,其域中的大多数安全工作都是孤立的,并散布在基础技术之间。这导致了整体安全性的晦涩视野。在这项工作中,我们试图通过提出一个特定领域的威胁建模框架来解决此问题。通过从各种各样的安全文献中收集到,我们系统地将移动通信的攻击组织为各种策略和技术。我们的框架旨在根据其攻击阶段对对抗性行为进行建模,并将其用作常见的分类矩阵。我们还提供了使用框架单独建模攻击并将其与类似攻击进行比较的具体示例。
Due to the complex nature of mobile communication systems, most of the security efforts in its domain are isolated and scattered across underlying technologies. This has resulted in an obscure view of the overall security. In this work, we attempt to fix this problem by proposing a domain-specific threat modeling framework. By gleaning from a diverse and large body of security literature, we systematically organize the attacks on mobile communications into various tactics and techniques. Our framework is designed to model adversarial behavior in terms of its attack phases and to be used as a common taxonomy matrix. We also provide concrete examples of using the framework for modeling the attacks individually and comparing them with similar ones.