首页> 外文会议>IEEE International Conference on Software Quality, Reliability and Security >FESR: A Framework for Eliciting Security Requirements Based on Integration of Common Criteria and Weakness Detection Formal Model
【24h】

FESR: A Framework for Eliciting Security Requirements Based on Integration of Common Criteria and Weakness Detection Formal Model

机译:FESR:基于共同标准的整合和弱点检测正式模型的诱因安全要求的框架

获取原文

摘要

It is critical and foremost to come up with the corresponding security requirements first which the following implementations are based on. However, previous security requirement elicitation work based on Common Criteria (CC) rarely addresses the detailed elicitation process of threats from specific functional requirements, which thus results in the widen gap between specific functional requirements and their corresponding threats. To this end, this paper proposes a framework for eliciting corresponding security requirements of specific functional requirements from the requirements specification. A formal model is built in the framework to assist requirement analysts in half-automatic collecting threats. To enhance the framework's automaticity and reusability, a security property base is constructed based on authoritative sources of security properties to support the framework. A practical information system is applied to verify the framework's practicability. Finally the framework's advantages and limitations are discussed thoroughly compared with previous approaches and useful insights are revealed.
机译:首先提出了相应的安全要求至关重要,首先提出以下实现是基于的。但是,基于公共标准(CC)的先前的安全要求阐述了促进工作,很少处理特定功能要求的威胁的详细诱因过程,从而导致特定功能要求与其相应威胁之间的差距拓宽差距。为此,本文提出了一种框架,用于从需求规范中引出特定功能要求的相应安全要求。正式模型建立在框架内,以帮助要求分析师半自动收集威胁。为了增强框架的自动和可重用性,基于权威的安全属性来源构建安全属性库以支持框架。应用实用信息系统以验证框架的实用性。最后,将框架的优势和限制彻底讨论,与先前的方法进行了彻底,并揭示了有用的见解。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号