首页> 外文会议>Embedded and Ubiquitous Computing, EUC, 2008 IEEE/IFIP International Conference on >A Systematic Framework for Structured Object-Oriented Security Requirements Analysis in Embedded Systems
【24h】

A Systematic Framework for Structured Object-Oriented Security Requirements Analysis in Embedded Systems

机译:嵌入式系统中结构化的面向对象的安全需求分析的系统框架

获取原文

摘要

The primary goal of this paper is to develop a structured object-oriented security requirements analysis methodology for the elicitation and analysis of security requirements in embedded systems. There are several approaches to elicit, analyze and specify security requirements in embedded systems ranging from formal mathematical models for proof of certain security properties to informal methods that are easily understood. Applicability of formal security models is limited because they are complex and it is time consuming to develop. On the other hand, informal security requirements analysis methods are not integrated with conceptual models in requirements analysis, and although both external and internal threats have been dealt using use cases and misuse cases, they provide no process for analyzing both internal and external threats in a structured manner. This paper discusses a structured object-oriented security requirements analysis methodology for the elicitation and analysis of security requirements in embedded systems. It is capable of identifying hierarchically both external and internal threats posed by both external and internal actors of a system level by level. It is illustrated and validated by security requirements analysis for an advanced embedded power grid control system.
机译:本文的主要目标是开发一种结构化的面向对象的安全需求分析方法,以用于嵌入式系统中的安全需求的引发和分析。有多种方法可以在嵌入式系统中引发,分析和指定安全性要求,从用于证明某些安全性的形式化数学模型到易于理解的非正式方法,不一而足。正式安全模型的适用性受到限制,因为它们很复杂并且开发很耗时。另一方面,非正式的安全需求分析方法并未与需求分析中的概念模型集成在一起,尽管虽然已使用用例和滥用案例来处理外部和内部威胁,但它们没有提供用于分析内部和外部威胁的过程。结构化的方式。本文讨论了一种结构化的面向对象的安全性需求分析方法,用于引发和分析嵌入式系统中的安全性需求。它能够逐级识别系统的外部和内部参与者所构成的外部和内部威胁。通过对高级嵌入式电网控制系统的安全需求分析进行了说明和验证。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号