TY - GEN
T1 - ABC
T2 - 2019 INFOCOM IEEE Conference on Computer Communications Workshops, INFOCOM WKSHPS 2019
AU - Almashaqbeh, Ghada
AU - Bishop, Allison
AU - Cappos, Justin
N1 - Publisher Copyright:
© 2019 IEEE.
PY - 2019/4
Y1 - 2019/4
N2 - Cryptocurrencies are an emerging economic force, but there are concerns about their security. This is due, in part, to complex collusion cases and new threat vectors, that could be missed by conventional security assessment strategies. To address these issues, we propose ABC, an Asset-Based Cryptocurrency-focused threat modeling framework capable of identifying such risks. ABC's key innovation is the use of collusion matrices. A collusion matrix forces a threat model to cover a large space of threat cases while simultaneously manages this process to prevent it from being overly complex. We demonstrate that ABC is effective by presenting real-world use cases and by conducting a user study. The user study showed that around 71% of those who used ABC were able to identify financial security threats, as compared to only 13% of participants who used the popular framework STRIDE.
AB - Cryptocurrencies are an emerging economic force, but there are concerns about their security. This is due, in part, to complex collusion cases and new threat vectors, that could be missed by conventional security assessment strategies. To address these issues, we propose ABC, an Asset-Based Cryptocurrency-focused threat modeling framework capable of identifying such risks. ABC's key innovation is the use of collusion matrices. A collusion matrix forces a threat model to cover a large space of threat cases while simultaneously manages this process to prevent it from being overly complex. We demonstrate that ABC is effective by presenting real-world use cases and by conducting a user study. The user study showed that around 71% of those who used ABC were able to identify financial security threats, as compared to only 13% of participants who used the popular framework STRIDE.
UR - http://www.scopus.com/inward/record.url?scp=85073265639&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=85073265639&partnerID=8YFLogxK
U2 - 10.1109/INFCOMW.2019.8845101
DO - 10.1109/INFCOMW.2019.8845101
M3 - Conference contribution
T3 - INFOCOM 2019 - IEEE Conference on Computer Communications Workshops, INFOCOM WKSHPS 2019
SP - 859
EP - 864
BT - INFOCOM 2019 - IEEE Conference on Computer Communications Workshops, INFOCOM WKSHPS 2019
PB - Institute of Electrical and Electronics Engineers Inc.
Y2 - 29 April 2019 through 2 May 2019
ER -