首页> 外文会议>Brazilian Conference on Intelligent Systems >Automatic Identification of Security Risks in Edicts for Software Procurement
【24h】

Automatic Identification of Security Risks in Edicts for Software Procurement

机译:自动识别软件采购法令中的安全风险

获取原文

摘要

Brazilian Federal Institutions must obtain software tools by procurement, requiring that their software teams develop, verify and audit their specifications to ensure that software security risks concerns are clearly included in edicts. This work presents the Automated Analyst of Edicts tool for aiding the analysis of such document by automatically identifying the absence of relationships between its sentences and software security risks or security weaknesses concepts. This tool was tested on over 100 documents and compared to software security experts' performance for multi-label classification into five of the OWASP Top Ten risks. Specificity of 83% was achieved when analyzing individual sentences for multiple risks, and 90% negative prediction probability when applied to specific risk sentence relationships.
机译:巴西联邦机构必须通过采购获得软件工具,要求其软件团队开发,验证和审核其规格,以确保法令中明确包括对软件安全风险的关注。这项工作介绍了自动法令分析工具,通过自动识别句子与软件安全风险或安全弱点概念之间是否不存在关系,来协助对此类文档进行分析。该工具已在100多个文档上进行了测试,并与软件安全专家的性能进行了比较,以将多标签分类为OWASP十大风险中的五种。当对单个句子进行多重风险分析时,达到83%的特异性;当应用于特定的风险句子关系时,达到90%的负面预测概率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号