Penetration Testing mailing list archives

Re: Attack trees


From: mjacobs.1 () gmail com
Date: 8 Dec 2005 17:09:31 -0000

Christophe,

I've worked quite extensively building attack trees with the Amenaza tool. It is quite stable, has the logic features 
you'll most likely need and it looks pretty too. The downside is that it doesn't have an API, so automatically 
generating attack trees is not possible. I used the tool for about a year with great success.

Isograph, which specializes in fault modeling tools developed a specialized attack tree software. It's called 
AttackTree+. It may not be as pretty as the amenaza tool, but it is much more open and possibly has more features. It 
lets you programmatically create trees using imported data.

Either way, both are very expensive, so I hope you have a good source of funding - as well as a massive plotter or 
projector for presentation.

MJ
Security Consultant

------------------------------------------------------------------------------
Audit your website security with Acunetix Web Vulnerability Scanner: 

Hackers are concentrating their efforts on attacking applications on your 
website. Up to 75% of cyber attacks are launched on shopping carts, forms, 
login pages, dynamic content etc. Firewalls, SSL and locked-down servers are 
futile against web application hacking. Check your website for vulnerabilities 
to SQL injection, Cross site scripting and other web attacks before hackers do! 
Download Trial at:

http://www.securityfocus.com/sponsor/pen-test_050831
-------------------------------------------------------------------------------


Current thread: