Attack trees are widely used by engineers to analyze and document threats during system design. They are also particularly valuable for supporting the risk analysis of systems. Despite advancements in automation, the construction of these trees is often manual, leading to errors and the potential to overlook unconventional attack vectors. This paper introduces a novel method and tool that addresses a gap in existing literature: generating attack trees early in the design stage from a textual specification of the system, written in natural language. By leveraging natural language processing and large language models, this approach helps engineers identify threats concurrently with the initial design of the system, thus avoiding time-consuming re-engineering later on. Additionally, the paper introduces metrics to evaluate the syntactic and semantic correctness of the generated attack trees. Our contributions are assessed using attack trees generated from three different system specifications, with a comparative analysis based on the defined metrics between trees generated by the tool and those created by engineers. From these assessments, we have discovered that our methodology produces attack trees at a quality not that far off from that of an individual engineer.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Automated Attack Tree Generation Using Artificial Intelligence and Natural Language Processing

  • Alan Birchler De Allende,
  • Bastien Sultan,
  • Ludovic Apvrille

摘要

Attack trees are widely used by engineers to analyze and document threats during system design. They are also particularly valuable for supporting the risk analysis of systems. Despite advancements in automation, the construction of these trees is often manual, leading to errors and the potential to overlook unconventional attack vectors. This paper introduces a novel method and tool that addresses a gap in existing literature: generating attack trees early in the design stage from a textual specification of the system, written in natural language. By leveraging natural language processing and large language models, this approach helps engineers identify threats concurrently with the initial design of the system, thus avoiding time-consuming re-engineering later on. Additionally, the paper introduces metrics to evaluate the syntactic and semantic correctness of the generated attack trees. Our contributions are assessed using attack trees generated from three different system specifications, with a comparative analysis based on the defined metrics between trees generated by the tool and those created by engineers. From these assessments, we have discovered that our methodology produces attack trees at a quality not that far off from that of an individual engineer.