首页> 外文会议>Hawaii International Conference on System Sciences >A Rigorous Methodology for Security Architecture Modeling and Verification
【24h】

A Rigorous Methodology for Security Architecture Modeling and Verification

机译:安全架构建模和验证的严格方法

获取原文

摘要

This paper introduces a rigorous methodology for utilizing threat modeling in building secure software architectures using SAM (Software Architecture Modeling framework) and verifying them formally using Symbolic Model Checking. Security mitigations are expressed as constraints over a high-level SAM model and are used to refine it into a secure constrained model. We also, propose a translation from SAM Secure models into the SMV model checker where the threats and the elicited security properties from the threat modeling process are used as inputs to the verification phase as well. This method is developed with the aim of bridging the gap between informal security requirements and their formal representation and verification.
机译:本文介绍了使用SAM(软件架构建模框架)建立安全软件架构中的威胁建模的严格方法,并使用符号模型检查正式验证它们。安全性缓解在高级SAM模型上表示为约束,并用于将其改进到安全约束模型中。我们还提出从SAM安全模型转换到SMV模型检查器,其中威胁建模过程的威胁和引出的安全性属性也被用作验证阶段的输入。这种方法是通过拓展非正规安全要求与其正式代表性和验证之间的差距而开发的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号