
Managing vulnerabilities with respect to the design of systems is essential to securing systems and establishing their trustworthiness. Until now, there has been no modelling tool to support vulnerability management within the context of system design. We present a new, open-source extension of a systems security design and assessment tool. First and foremost, this extension integrates a pertinent vulnerability management domain ontology into the tool's underlying metamodel. Based on the extended metamodel, the enriched tool supports importing information from vulnerability-related knowledge bases as well as capturing new vulnerability information and security rules. This information can then be used in an integrative and scalable form to analyse and reason about the security of systems designs. The extended tool now includes an automated reasoning mechanism for establishing the vulnerability posture of systems designs.
Modeling methodologies Security and privacy, Security by design, Vulnerability management Security and privacy, Modeling and simulation, Model development and analysis, Systems security, Model driven engineering, Computing methodologies, Vulnerability management, CCS CONCEPTS, Software and application security, 004, [INFO]Computer Science [cs], Software security engineering, Threat modelling
Modeling methodologies Security and privacy, Security by design, Vulnerability management Security and privacy, Modeling and simulation, Model development and analysis, Systems security, Model driven engineering, Computing methodologies, Vulnerability management, CCS CONCEPTS, Software and application security, 004, [INFO]Computer Science [cs], Software security engineering, Threat modelling
| selected citations These citations are derived from selected sources. This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | 1 | |
| popularity This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network. | Average | |
| influence This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | Average | |
| impulse This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network. | Average |
