首页> 外文会议>Asia-Pacific Software Engineering Conference >An Asset-Based Assistance for Secure by Design
【24h】

An Asset-Based Assistance for Secure by Design

机译:由设计安全的基于资产的援助

获取原文

摘要

With the growing numbers of security attacks causing more and more serious damages in software systems, security cannot be added as an afterthought in software development. It has to be built in from the early development phases such as requirement and design. The role responsible for designing a software system is termed an “architect”, knowledgeable about the system architecture design, but not always well-trained in security. Moreover, involving other security experts into the system design is not always possible due to time-to-market and budget constraints. To address these challenges, we propose to define an asset-based security assistance in this paper, to help architects design secure systems even if these architects have limited knowledge in security. This assistance helps alert threats, and integrate the security controls over vulnerable parts of system into the architecture model. The central concept enabling this assistance is that of asset. We apply our proposal on a telemonitoring case study to show that automating such an assistance is feasible.
机译:随着越来越多的安全攻击导致软件系统中的越来越严重的损害,无法将安全性添加为软件开发的事后。它必须从早期开发阶段内置,例如要求和设计。负责设计软件系统的角色被称为“架构师”,了解系统架构设计,但并不总是在安全性中训练。此外,由于上市时间和预算限制,涉及其他安全专家进入系统设计并不总是可能的。为了解决这些挑战,我们建议在本文中定义基于资产的安全援助,以帮助建筑师设计安全系统,即使这些架构师在安全知识有限。此辅助有助于警告威胁,并将安全控件集成到系统的易受攻击部分中的安全控制。使这种援助能够实现这一援助的是资产。我们在一项远程案例研究中应用我们的提案,以表明自动化这种援助是可行的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号