Case Study: Security of System for Remote Management of Windows

Tarik Dervišević, Sabina Baraković, J. Husić
{"title":"Case Study: Security of System for Remote Management of Windows","authors":"Tarik Dervišević, Sabina Baraković, J. Husić","doi":"10.2478/bhee-2020-0007","DOIUrl":null,"url":null,"abstract":"Abstract In the process of designing and forming each system, it is necessary to identify potential vulnerabilities and threats to that system and to include appropriate countermeasures. The process that helps to find the problem in the first phase of design is called threat modeling. Threat modeling is based on the idea that every system has valuable resources that need to be protected. These resources have certain weak points that internal or external threats can use to harm them, while there are as well countermeasures used to mitigate them. Therefore, this paper analyses the security of a Web of Things (WoT)-based system for remote management of windows, which is in the design stage by using a threat modeling approach based on STRIDE and DREAD. The results obtained through Microsoft Threat Modeling Tool (MTMT) justified the use of threat modeling in the design phase given that we have identified in total 118 threats, with Elevation of privilege class of threats being the most prominent ones. The Information disclosure threats are found to be the ones characterized as medium and low risk ones, while the most represented high-risk threats again come from the Elevation of privilege class of threats.","PeriodicalId":236883,"journal":{"name":"B&H Electrical Engineering","volume":"84 6","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"B&H Electrical Engineering","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.2478/bhee-2020-0007","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Abstract In the process of designing and forming each system, it is necessary to identify potential vulnerabilities and threats to that system and to include appropriate countermeasures. The process that helps to find the problem in the first phase of design is called threat modeling. Threat modeling is based on the idea that every system has valuable resources that need to be protected. These resources have certain weak points that internal or external threats can use to harm them, while there are as well countermeasures used to mitigate them. Therefore, this paper analyses the security of a Web of Things (WoT)-based system for remote management of windows, which is in the design stage by using a threat modeling approach based on STRIDE and DREAD. The results obtained through Microsoft Threat Modeling Tool (MTMT) justified the use of threat modeling in the design phase given that we have identified in total 118 threats, with Elevation of privilege class of threats being the most prominent ones. The Information disclosure threats are found to be the ones characterized as medium and low risk ones, while the most represented high-risk threats again come from the Elevation of privilege class of threats.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
案例研究:Windows远程管理系统的安全性
在设计和形成每个系统的过程中,都需要识别该系统的潜在漏洞和威胁,并制定相应的对策。在设计的第一阶段帮助发现问题的过程称为威胁建模。威胁建模基于这样的理念:每个系统都有需要保护的宝贵资源。这些资源有某些弱点,内部或外部威胁可以利用这些弱点来伤害它们,同时也有一些对策可以用来减轻这些弱点。因此,本文采用基于STRIDE和DREAD的威胁建模方法,对处于设计阶段的基于物联网(Web of Things, WoT)的窗口远程管理系统的安全性进行了分析。通过Microsoft威胁建模工具(MTMT)获得的结果证明了在设计阶段使用威胁建模是合理的,因为我们已经识别了总共118个威胁,其中提升特权类威胁是最突出的威胁。信息披露威胁以中、低风险类型的威胁最为明显,而最具代表性的高风险威胁仍然来自于特权提升类的威胁。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Increasing the Capacity of the Distribution Network by Changing Consumers’ Habits - Case Study Long-Range Remote Control Based on LoRa Transceivers Digital Transformation Path of Manually Collected Meter Reading Data Profile Optimisation in Real Distribution Networks (Case Study Long MV Feeder) New Functions of VSC Based HVDC Transmission Systems that Can Effectively Support the Future South-East European Grid with Low Inertia and Large Amount of Res Generation
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1