首页> 外文会议>IEEE International Workshop on Requirements Patterns >Pattern-based security requirements specification using ontologies and boilerplates
【24h】

Pattern-based security requirements specification using ontologies and boilerplates

机译:基于模式的安全要求使用本体和锅炉的规范

获取原文

摘要

The task of specifying and managing security requirements (SR) is a challenging one. Usually SR are often neglected or considered too late - leading to poor design, and cost overruns. Also, there is scarce expertise in managing SR, because most requirements engineering teams do not include security experts, which leads to prevalence of too vague or overly specific SR. In this work, we present an ontology-based approach that uses predefined pattern-based templates - requirements boilerplates - to aid requirements engineers in the formulation of SR. We realized the approach via a prototype tool that enables the formulation of SR from textual misuse case (TMUC) descriptions of security threat scenarios. The results from a preliminary evaluation suggest the viability of the proposed approach, in that the tool was judged as easy to use, supports reuse, and facilitates the formulation of good quality SR.
机译:指定和管理安全要求(SR)的任务是一个具有挑战性的。 通常SR通常被忽视或考虑太晚 - 导致设计不佳,成本超支。 此外,管理SR的稀缺专业知识,因为大多数需求工程团队不包括安全专家,这导致过于模糊或过于特定的SR的普遍存在。 在这项工作中,我们介绍了一种基于本体的方法,它使用基于预定的基于模式的模板 - 需求锅炉 - 以帮助要求工程师在SR的配方中。 我们通过原型工具实现了方法,该方法可以从文本误用案例(TMUC)描述安全威胁方案的描述。 初步评估的结果表明了所提出的方法的可行性,因为该工具被判断为易于使用,支持重用,并促进配方质量SR。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号