首页> 外文会议>IEEE International Conference on Self-Adaptive and Self-Organizing Systems >Self-Adaptation Strategies to Maintain Security Assurance Cases
【24h】

Self-Adaptation Strategies to Maintain Security Assurance Cases

机译:维持安全保障案例的自适应策略

获取原文

摘要

Information system security certification involves guaranteeing that mechanisms are deployed to comply with selected security controls, such as those in the NIST SP800-53, at acceptable levels of confidence and risk. When a system can self-adapt at runtime, it may alter its functional behavior to address a defect or anomaly. This functional change can impact associated security controls, potentially making the adapted system vulnerable to security threats. Performing security control assurance adaptation along with functional adaptation would allow both compliance confidence and risk analysis to accompany functional adaptation analysis. The need for this dual assessment implies security control compliance should be expressed such that an adaptation can be reflected as part of its compliance status. In this paper, we represent security controls and their deployed mechanisms in terms of security assurance cases. We define a template using Goal Structuring Notation (GSN) that follows the NIST SP800-53 control statement structure. We define three adaptation operators to dictate how and where a change impacts relevant assurance cases. The objective is to express and manage the controls and adaptation operators so that changes to a security assurance case can be embedded and traced within the executing system to make it security aware. We illustrate the approach using a small case study and a security control for systems and communications protection, taken from the NIST SP800-53.
机译:信息系统安全认证涉及确保以可接受的置信度和风险水平部署机制以符合选定的安全控制,例如NIST SP800-53中的那些。当系统可以在运行时自适应时,它可以更改其功能行为以解决缺陷或异常。此功能更改可能会影响相关的安全控制,从而可能使适配的系统容易受到安全威胁的攻击。与功能调整一起执行安全控制保证调整将允许合规置信度和风险分析与功能调整分析一起进行。对这种双重评估的需求意味着应该表达安全控制合规性,以便适应性可以反映为其合规性状态的一部分。在本文中,我们从安全保证案例的角度介绍了安全控制及其部署的机制。我们使用遵循NIST SP800-53控制语句结构的目标结构表示法(GSN)定义模板。我们定义了三个适应运算符,以指示更改如何以及在何处影响相关的保证案例。目的是表达和管理控件和适配运算符,以便可以将对安全保证案例的更改嵌入并跟踪到正在执行的系统中,以使其具有安全意识。我们使用来自NIST SP800-53的小案例研究以及用于系统和通信保护的安全控制来说明该方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号