...
首页> 外文期刊>Software Quality Journal >Security quality model: an extension of Dromey’s model
【24h】

Security quality model: an extension of Dromey’s model

机译:安全质量模型:Dromey模型的扩展

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

The quantity of sensitive data that is stored, processed and transmitted has increased many folds in recent years. With this dramatic increase, comes the need to ensure that the data remain trustworthy, confidential and available at all times. Nonetheless, the recent spate of high-profile security incidents shows that software-based systems remain vulnerable due to the presence of serious security defects. Therefore, there is a clear need to improve the current state of software development to guide the development of more secure software. To this end, we propose a security quality model that provides a framework to identify known security defects, their fixes, the underlying low-level software components along with the properties that positively influence the overall security of the product. The proposed model is based on Dromey’s quality model that addresses the core issue of quality by providing explicit guidelines on how to build quality into a product. Furthermore, to incorporate security, we have introduced several new model components and model construction guidelines as Dromey’s model does not address security explicitly and the model construction guidelines are not specific enough. We use well-known defects and security controls to construct the model as a proof of concept. The constructed model can be used by the programmers during development and can also be used by the quality engineers for audit purposes. We also propose an automated environment in which the model can be used in practice.
机译:近年来,存储,处理和传输的敏感数据数量增加了许多倍。随着这一惊人的增长,需要确保数据始终保持可信,机密和可用。尽管如此,最近发生的一系列引人注目的安全事件表明,由于存在严重的安全缺陷,基于软件的系统仍然容易受到攻击。因此,显然需要改善软件开发的当前状态,以指导更安全的软件的开发。为此,我们提出了一个安全质量模型,该模型提供了一个框架来识别已知的安全缺陷,其修补程序,底层的低级软件组件以及对产品的整体安全性产生积极影响的属性。提议的模型基于Dromey的质量模型,该模型通过提供有关如何在产品中构建质量的明确准则来解决质量的核心问题。此外,为了合并安全性,我们引入了几个新的模型组件和模型构建准则,因为Dromey的模型并未明确解决安全问题,并且模型构建准则还不够具体。我们使用众所周知的缺陷和安全控制来构建模型以作为概念证明。构造的模型可以在开发过程中供程序员使用,也可以由质量工程师用于审核目的。我们还提出了一个可以在其中实际使用模型的自动化环境。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号