【24h】

Using Security and Domain Ontologies for Security Requirements Analysis

机译:使用安全性和域本体进行安全性需求分析

获取原文

摘要

Recent research has argued about the importance of considering security during Requirements Engineering (RE) stage. Literature also emphasizes the importance of using ontologies to facilitate requirements elicitation. Ontologies are known to be rich sources of knowledge, and, being structured and equipped with reasoning features, they form a powerful tool to handle requirements. We believe that security being a multi-faceted problem, a single security ontology is not enough to guide SR Engineering (SRE) efficiently. Indeed, security ontologies only focus on technical and domain independent aspects of security. Therefore, one can hypothesize that domain knowledge is needed too. Our question is 'how to combine the use of security ontologies and domain ontologies to guide requirements elicitation efficiently and effectively?' We propose a method that exploits both types of ontologies dynamically through a collection of heuristic production rules. We demonstrate that the combined use of security ontologies with domain ontologies to guide SR elicitation is more effective than just relying on security ontologies. This paper presents our method and reports a preliminary evaluation conducted through critical analysis by experts. The evaluation shows that the method provides a good balance between the genericity with respect to the ontologies (which do not need to be selected in advance), and the specificity of the elicited requirements with respect to the domain at hand.
机译:最近的研究争论了在需求工程(RE)阶段考虑安全性的重要性。文献还强调了使用本体来促进需求启发的重要性。众所周知,本体是丰富的知识来源,并且通过结构化和配备推理功能,它们构成了处理需求的强大工具。我们认为,安全性是一个多方面的问题,一个安全性本体不足以有效地指导SR工程(SRE)。确实,安全本体仅关注安全的技术和域独立方面。因此,人们可以假设也需要领域知识。我们的问题是“如何将安全本体和域本体的使用结合起来,以有效地指导需求引发?”我们提出了一种通过启发式生产规则来动态利用两种类型的本体的方法。我们证明,结合使用安全本体和域本体来引导SR引发比仅依赖安全本体更有效。本文介绍了我们的方法,并报告了专家通过严格分析进行的初步评估。评估表明,该方法在关于本体的通用性(不需要预先选择)与针对当前域的要求的特异性之间提供了良好的平衡。

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号