首页> 外文会议>34th Annual IEEE Computer Software and Applications Conference >Security in Context: Analysis and Refinement of Software Architectures
【24h】

Security in Context: Analysis and Refinement of Software Architectures

机译:上下文中的安全性:软件体系结构的分析和完善

获取原文

摘要

Security analysis methods can provide correct yet meaningless results if the assumptions underlying the model do not conform to reality. We present an approach to analyze the security of software-intensive system architectures that focusses on making these underlying assumptions explicit, so that they can be taken into account. Starting from an Alloy model of a software architecture, a set of constraints is elicited by leveraging model relaxation techniques. These constraints form a minimal but sufficient condition that the system must meet in order to realise its security requirements. As the approach starts from the minimal guarantees that the system environment offers, it does not depend on an explicit attacker model and can take arbitrary attacker behaviour into account. As it is iterative, it is possible to constructively integrate the approach in a secure software development life cycle. Our results are illustrated by means of a case study.
机译:如果模型基础的假设与现实不符,则安全分析方法可以提供正确但无意义的结果。我们提出了一种分析软件密集型系统体系结构安全性的方法,该方法侧重于使这些基本假设变得明确,以便可以将它们考虑在内。从软件体系结构的Alloy模型开始,利用模型松弛技术会引发一组约束。这些约束形成了系统必须满足的最小但足够的条件,以实现其安全性要求。由于该方法从系统环境提供的最小保证开始,因此它不依赖于明确的攻击者模型,并且可以考虑任意的​​攻击者行为。由于它是迭代的,因此可以在安全的软件开发生命周期中建设性地集成该方法。通过案例研究说明了我们的结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号