open access publication

Article, 2024

Survey: Automatic generation of attack trees and attack graphs

Computers and Security, ISSN 0167-4048, Volume 137, 10.1016/j.cose.2023.103602

Contributors

Konsta A.-M. 0000-0002-0206-5217 (Corresponding author) [1] Lafuente A.L. 0000-0001-7405-0818 [1] Spiga B. [1] Dragoni N. 0000-0001-9575-2990 [1]

Affiliations

  1. [1] Technical University of Denmark
  2. [NORA names: DTU Technical University of Denmark; University; Denmark; Europe, EU; Nordic; OECD]

Abstract

Graphical security models constitute a well-known, user-friendly way to represent the security of a system. These classes of models are used by security experts to identify vulnerabilities and assess the security of a system. The manual construction of these models can be tedious, especially for large enterprises. Consequently, the research community is trying to address this issue by proposing methods for the automatic generation of such models. In this work, we present a survey illustrating the current status of the automatic generation of two popular kinds of graphical security models: Attack Trees and Attack Graphs. The goal of this survey is to present the current methodologies used in the field, compare them, and present the challenges and future directions to the research community.

Keywords

Attack graphs, Attack trees, Automatic generation, Graphical security models, Survey, Threat modeling

Funders

  • Innovation Fund Denmark and the Digital Research Centre Denmark

Data Provider: Elsevier