Authors
Ragib Hasan, Suvda Myagmar, Adam J Lee, William Yurcik
Publication date
2005/11/11
Book
Proceedings of the 2005 ACM workshop on Storage security and survivability
Pages
94-102
Description
The growing number of storage security breaches as well as the need to adhere to government regulations is driving the need for greater storage protection. However, there is the lack of a comprehensive process to designing storage protection solutions. Designing protection for storage systems is best done by utilizing proactive system engineering rather than reacting with ad hoc countermeasures to the latest attack du jour. The purpose of threat modeling is to organize system threats and vulnerabilities into general classes to be addressed with known storage protection techniques. Although there has been prior work on threat modeling primarily for software applications, to our knowledge this is the first attempt at domain-specific threat modeling for storage systems. We discuss protection challenges unique to storage systems and propose two different processes to creating a threat model for storage systems: one …
Total citations
200620072008200920102011201220132014201520162017201820192020202120222023202487743473411915627972
Scholar articles
R Hasan, S Myagmar, AJ Lee, W Yurcik - Proceedings of the 2005 ACM workshop on Storage …, 2005