首页> 外文会议>2010 IEEE International Conference on Technologies for Homeland Security >Computer-assisted validation and verification of cybersecurity requirements
【24h】

Computer-assisted validation and verification of cybersecurity requirements

机译:计算机辅助验证和验证网络安全要求

获取原文

摘要

Errors in requirements are often a contributing cause of the failure of critical infrastructure and their underlying information systems to adequately guard against cyber intrusions and withstand cyber attacks. However, detecting errors in the cybersecurity requirements, and for requirements in general, is a challenging task. In this paper we describe how computer-aided formal verification and validation can be leveraged to address the challenge of correctly capturing natural language cybersecurity requirements, converting the natural language statements into formal requirements specifications, and then checking the formal specifications to ensure that they match the original intent of the stakeholders. Our approach centers on creating a one-to-one mapping between natural language requirements and UML statechart assertions. Statechart assertions are Boolean statements about the expected behavior of the system, expressed as UML statecharts. The set of assertions created by the security or software engineer is a formal model of the system's requirements. We demonstrate our approach using examples of formally specifying and validating requirements for correct cyber system behaviors and the detection of illegal business schemes in choreographed web services.
机译:需求中的错误通常是导致关键基础架构及其底层信息系统无法充分防御网络入侵和抵御网络攻击的原因。但是,检测网络安全要求中的错误以及一般要求中的错误是一项具有挑战性的任务。在本文中,我们描述了如何利用计算机辅助的形式验证和确认来应对以下挑战:正确捕获自然语言网络安全要求,将自然语言声明转换为形式要求规范,然后检查形式规范以确保它们与标准规范相匹配。利益相关者的初衷。我们的方法着眼于在自然语言需求和UML状态图声明之间创建一对一的映射。状态图断言是有关系统预期行为的布尔语句,表示为UML状态图。由安全或软件工程师创建的一组断言是系统需求的正式模型。我们以正式指定和验证对正确的网络系统行为的要求以及在经过编排的Web服务中检测非法业务方案的示例为例,演示了我们的方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号