首页> 外文会议>International working conference on requirements engineering: foundation for software quality >Analyzing and Enforcing Security Mechanisms on Requirements Specifications
【24h】

Analyzing and Enforcing Security Mechanisms on Requirements Specifications

机译:分析和执行需求规范的安全机制

获取原文

摘要

[Context and motivation] Security mechanisms, such as firewalls and encryption, operationalize security requirements, such as confidentiality and integrity. [Question/problem] Although previous work has pointed out that the application of a security mechanism affects system specifications, there is no systematic approach to describe and analyze this impact. [Principal ideas/results] In this paper, we investigate more than 40 security mechanisms that are well documented in security pattern repositories in order to better understand what they are and how they function. [Contribution] Based on this study, we propose a conceptual model for security mechanisms, and evaluate this model against 20 security mechanisms. Using the conceptual model, we provide a systematic process for analyzing and enforcing security mechanisms on system requirements. We also develop a prototype tool to facilitate the application and evaluation of our approach.
机译:[上下文和动机]安全机制(例如防火墙和加密)可实现安全要求,例如机密性和完整性。 [问题/问题]尽管先前的工作已经指出安全机制的应用会影响系统规范,但是没有系统的方法来描述和分析这种影响。 [主要思想/结果]在本文中,我们研究了40多种安全机制,这些机制在安全模式存储库中都有详细记录,以便更好地了解它们的功能以及作用方式。 [贡献]基于此研究,我们提出了一种安全机制的概念模型,并针对20种安全机制对该模型进行了评估。使用概念模型,我们提供了一个系统的过程,用于分析和执行针对系统要求的安全机制。我们还开发了一个原型工具,以促进我们方法的应用和评估。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号