首页> 外文会议>Software Engineering, 2004. ICSE 2004. Proceedings >Elaborating security requirements by construction of intentional anti-models
【24h】

Elaborating security requirements by construction of intentional anti-models

机译:通过构造有意的反模型来详细说明安全性要求

获取原文

摘要

Caring for security at requirements engineering time is a message that has finally received some attention recently. However, it is not yet very clear how to achieve this systematically through the various stages of the requirements engineering process. The paper presents a constructive approach to the modeling, specification and analysis of application-specific security requirements. The method is based on a goal-oriented framework for generating and resolving obstacles to goal satisfaction. The extended framework addresses malicious obstacles (called anti-goals) set up by attackers to threaten security goals. Threat trees are built systematically through anti-goal refinement until leaf nodes are derived that are either software vulnerabilities observable by the attacker or anti-requirements implementable by this attacker. New security requirements are then obtained as countermeasures by application of threat resolution operators to the specification of the anti-requirements and vulnerabilities revealed by the analysis. The paper also introduces formal epistemic specification constructs and patterns that may be used to support a formal derivation and analysis process. The method is illustrated on a Web-based banking system for which subtle attacks have been reported recently.
机译:在需求工程设计时关注安全性的消息最近终于引起了人们的关注。但是,还不清楚如何在需求工程过程的各个阶段中系统地实现这一目标。本文提出了一种针对特定应用程序安全性要求的建模,规范和分析的建设性方法。该方法基于用于生成和解决目标满意度障碍的面向目标的框架。扩展框架解决了攻击者为威胁安全目标而设置的恶意障碍(称为反目标)。威胁树是通过反目标优化系统地构建的,直到派生出叶节点为止,叶节点要么是攻击者可以观察到的软件漏洞,要么是攻击者可以实现的反需求。然后,通过将威胁解决方案运营商应用于分析所揭示的反需求和漏洞的规范,可以获得新的安全性要求作为对策。本文还介绍了可用于支持正式推导和分析过程的正式认知规范规范和模式。该方法在基于Web的银行系统中得到了说明,最近已经报道了该系统的细微攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号