【24h】

Development of a software security assessment instrument to reduce software security risk

机译:开发软件安全评估工具以降低软件安全风险

获取原文

摘要

The paper discusses joint work by the California Institute of Technology's Jet Propulsion Laboratory and the University of California at Davis (CC Davis) sponsored by the National Aeronautics and Space Administration to develop a security assessment instrument for the software development and maintenance life cycle. The assessment instrument is a collection of tools and procedures to support development of secure software. Specifically, the instrument offers a formal approach for engineering network security into software systems and application throughout the software development and maintenance life cycle. The security assessment instrument includes a Vulnerability Matrix (VMatrix) with platform/application, and signature fields in a database. The information in the VMatrix has become the basis for the Database of Vulnerabilities, Exploits, and Signatures (DOVES) at UC Davis. The instrument also includes a set of Security Assessment Tools (SAT), including the development of a property-based testing tool by UC Davis, to slice software code looking for specific vulnerability properties. A third component of the research is an investigation into the verification of software designs for compliance to security properties. This is based on innovative model checking approaches that will facilitate the development and verification of software security models.
机译:本文讨论了由美国国家航空航天局赞助的加州理工学院喷气推进实验室与加州大学戴维斯分校(CC Davis)的联合工作,以开发用于软件开发和维护生命周期的安全评估工具。评估工具是支持安全软件开发的工具和过程的集合。特别是,该仪器为在整个软件开发和维护生命周期中将网络安全工程化到软件系统和应用程序中提供了一种正式方法。安全评估工具包括带有平台/应用程序的漏洞矩阵(VMatrix),以及数据库中的签名字段。 VMatrix中的信息已成为UC Davis漏洞,漏洞和特征数据库(DOVES)的基础。该工具还包括一组安全评估工具(SAT),其中包括UC Davis开发的基于属性的测试工具,以对软件代码进行切片以查找特定的漏洞属性。该研究的第三部分是调查软件设计是否符合安全性要求。这基于创新的模型检查方法,这将有助于软件安全模型的开发和验证。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号