首页> 外文会议>IEEE International Conference on Software Quality, Reliability and Security >FESR: A Framework for Eliciting Security Requirements Based on Integration of Common Criteria and Weakness Detection Formal Model
【24h】

FESR: A Framework for Eliciting Security Requirements Based on Integration of Common Criteria and Weakness Detection Formal Model

机译:FESR:一种基于通用标准和弱点检测形式模型的集成的安全要求框架

获取原文

摘要

It is critical and foremost to come up with the corresponding security requirements first which the following implementations are based on. However, previous security requirement elicitation work based on Common Criteria (CC) rarely addresses the detailed elicitation process of threats from specific functional requirements, which thus results in the widen gap between specific functional requirements and their corresponding threats. To this end, this paper proposes a framework for eliciting corresponding security requirements of specific functional requirements from the requirements specification. A formal model is built in the framework to assist requirement analysts in half-automatic collecting threats. To enhance the framework's automaticity and reusability, a security property base is constructed based on authoritative sources of security properties to support the framework. A practical information system is applied to verify the framework's practicability. Finally the framework's advantages and limitations are discussed thoroughly compared with previous approaches and useful insights are revealed.
机译:至关重要的是,首先要提出相应的安全要求,这些安全要求是以下实现的基础。但是,以前基于通用标准(CC)的安全需求获取工作很少解决来自特定功能需求的威胁的详细获取过程,因此导致特定功能需求与其对应威胁之间的差距越来越大。为此,本文提出了一个框架,用于从需求规范中得出特定功能需求的相应安全需求。在框架中构建了一个正式模型,以帮助需求分析人员半自动收集威胁。为了增强框架的自动化和可重用性,基于安全属性的权威来源构建了一个安全属性库来支持该框架。应用了一个实用的信息系统来验证框架的实用性。最后,与以前的方法相比,对该框架的优点和局限性进行了全面讨论,并揭示了有用的见解。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号