首页> 外文会议>Federated Conference on Computer Science and Information Systems >Formalization of Software Risk Assessment Results in Legal Metrology Based on ISO/IEC 18045 Vulnerability Analysis
【24h】

Formalization of Software Risk Assessment Results in Legal Metrology Based on ISO/IEC 18045 Vulnerability Analysis

机译:基于ISO / IEC 18045漏洞分析的合法计量中软件风险评估结果的形式化

获取原文

摘要

The Measuring Instruments Directive sets down essential requirements for measuring instruments subject to legal control in the EU. It dictates that a risk assessment must be performed before such instruments are put on the market. Because of the increasing importance of software in measuring instruments, a specifically tailored software risk assessment method has been previously developed and published. Related research has been done on graphical representation of threats by attack probability trees. The final stage is to formalize the method to prove its reproducibility and resilience against the complexity of future instruments. To this end, an inter-institutional comparison of the method is currently being conducted across national metrology institutes, while the weighing equipment manufacturers’ association CECIP has provided a new measuring instrument concept, as a significant example of complex instruments. Based on the results of the comparison, a template to formalize the software risk assessment method is proposed here.
机译:《测量仪器指令》规定了受欧盟法律控制的测量仪器的基本要求。它规定在将此类工具投放市场之前必须进行风险评估。由于软件在测量仪器中的重要性日益提高,因此以前专门开发和发布了专门定制的软件风险评估方法。已经通过攻击概率树对威胁的图形表示进行了相关研究。最后一步是使该方法正式化,以证明其可再现性和抵御未来仪器复杂性的能力。为此,目前正在全国计量机构之间对该方法进行机构间比较,而称重设备制造商协会CECIP提供了一种新的测量仪器概念,作为复杂仪器的重要示例。根据比较的结果,在此提出了一种形式化软件风险评估方法的模板。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号