作者: Henry Prakken , Dan Ionita , Roel Wieringa
DOI: 10.1007/978-3-642-40624-9_22
关键词:
摘要: This paper explores the idea that IT security risk assessment can be formalized as an argumentation game in which assessors argue about how system attacked by a threat agent and defended assessors. A architecture plus assumptions environment is specified ASPIC + theory, argument defined for exchanging arguments between hypothetical agents whether specification satisfies given requirement. Satisfaction always partial involves of The dynamic players both add elements to delete from specification. shown respect underlying logic any logically completed 'won' defender, requirement justified conclusion at stage game.