Abstract: Threat tree model can clearly or- ganize threat induction information and thus is widely used for risk analysis in software assur- ance. Threat tree will grow to complicated struc- tures, e.g., the number of nodes and branches, when the threat information grows to a huge vol- ume. To extend the scalability of the threat tree model, we propose a tree model with merged n- odes so as to largely decrease the number of nodes and branches. The formal model and dedicated algorithms are proposed in details. The exper- imental results show the practicality of Merge- Tree. We also formally analyze the soundness and completeness of the proposed model.
Keywords: Threat Tree, Semantics, Risk Analysis, Software Assurance
Cite this paper
Ping Chen, Jingjing Hu, Zhitao Wu, Ruoting Xiong, Wei Ren. (2022) MergeTree: a Tree Model with Merged Nodes for Threat Induction. International Journal of Mathematical and Computational Methods, 7 , 75-79

Copyright © 2022 Author(s) retain the copyright of this article. This article is published under the terms of the Creative Commons Attribution License 4.0


