首页> 外文会议>International Multi-Conference on Computing in the Global Information Technology >Finding Potential Threats in Several Security Targets for Eliciting Security Requirements
【24h】

Finding Potential Threats in Several Security Targets for Eliciting Security Requirements

机译:寻找诸多安全目标的潜在威胁,以引发安全要求

获取原文

摘要

Threats to existing systems help requirements analysts to elicit security requirements for a new system similar to such systems because security requirements specify how to protect the system against threats and similar systems require similar means for protection. We propose a method of finding potential threats that can be used for eliciting security requirements for such a system. The method enables analysts to find additional security requirements when they have already elicited one or a few threats. The potential threats are derived from several security targets (STs) in the Common Criteria. An ST contains knowledge related to security requirements such as threats and objectives. It also contains their explicit relationships. In addition, individual objectives are explicitly related to the set of means for protection, which are commonly used in any STs. Because we focus on such means to find potential threats, our method can be applied to STs written in any languages, such as English or French. We applied and evaluated our method to three different domains. In our evaluation, we enumerated all threat pairs in each domain. We then predicted whether a threat and another in each pair respectively threaten the same requirement according to the method. The recall of the prediction was more than 70% and the precision was 20 to 40% in three domains.
机译:对现有系统的威胁有助于要求分析师引发与此类系统类似的新系统的安全要求,因为安全要求指定如何保​​护系统免受威胁和类似系统需要类似的保护手段。我们提出了一种寻找潜在威胁的方法,该威胁可用于赋予这种系统的安全要求。该方法使分析人员能够在已经引发一个或几个威胁时找到额外的安全要求。潜在的威胁来自常见标准中的几个安全目标(STS)。 ST包含与安全要求相关的知识,例如威胁和目标。它还包含他们的显式关系。此外,个人目标明确地与用于保护的一组手段相关,这通常在任何ST中使用。因为我们专注于找到潜在威胁的方法,我们的方法可以应用于以任何语言编写的STS,例如英语或法语。我们应用并评估了三个不同域的方法。在我们的评估中,我们列举了每个域中的所有威胁对。然后,我们预测了每对中的威胁和另一个威胁,根据该方法威胁到相同的要求。预测的召回超过70%,三个域的精度为20至40%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号