首页> 外文会议>IEEE Cybersecurity Development >BP: Integrating Cyber Vulnerability Assessments Earlier into the Systems Development Lifecycle: A Methodology to Conduct Early-Cycle Cyber Vulnerability Assessments
【24h】

BP: Integrating Cyber Vulnerability Assessments Earlier into the Systems Development Lifecycle: A Methodology to Conduct Early-Cycle Cyber Vulnerability Assessments

机译:BP:将网络漏洞评估更早地集成到系统开发生命周期中:进行早期周期网络漏洞评估的方法

获取原文

摘要

During development of high assurance cyber systems, third-party security evaluations such as cyber vulnerability assessments (CVAs) and red teaming may not be conducted until after system implementation. This late in the systems development lifecycle (SDLC), mitigating a single implementation vulnerability may require altering the system requirements, architecture, and design, resulting in a cascade of secondary effects that necessitate additional implementation changes. This paper proposes to identify and mitigate vulnerabilities earlier in the SDLC by conducting early-cycle CVAs (eCVAs). eCVAs initiate the vulnerability assessment process earlier and integrate three CVAs into the SDLC. The three types of assessments include a requirements CVA to analyze system requirements specifications, an architecture and design CVA to evaluate architecture and design artifacts, and an implementation CVA with a focus on manual code review, static and dynamic analysis, and researching leveraged code for known vulnerabilities. This paper describes the three types of CVAs and outlines the results of a year-long pilot effort carried out by the Air Force Research Laboratory Information Directorate eCVA team.
机译:在开发高度安全的网络系统期间,可能要等到系统实施后才能进行第三方安全性评估,例如网络漏洞评估(CVA)和红色团队。在系统开发生命周期(SDLC)的后期,要缓解单个实施漏洞,可能需要更改系统要求,体系结构和设计,从而导致一系列次要影响,从而需要进行其他实施更改。本文建议通过进行早期周期CVA(eCVA)来识别和缓解SDLC中的漏洞。 eCVA会更早启动漏洞评估过程,并将三个CVA集成到SDLC中。三种类型的评估包括:需求CVA,用于分析系统需求规范;架构和设计CVA,用于评估架构和设计工件;以及实施CVA,其重点在于手动代码审查,静态和动态分析以及研究已知的杠杆代码漏洞。本文介绍了三种CVA,并概述了空军研究实验室信息局eCVA团队进行的为期一年的试点工作的结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号