首页> 外文会议>IEEE Cybersecurity Development Conference >BP: Integrating Cyber Vulnerability Assessments Earlier into the Systems Development Lifecycle: A Methodology to Conduct Early-Cycle Cyber Vulnerability Assessments
【24h】

BP: Integrating Cyber Vulnerability Assessments Earlier into the Systems Development Lifecycle: A Methodology to Conduct Early-Cycle Cyber Vulnerability Assessments

机译:BP:将网络漏洞评估集成到系统开发生命周期中:一种进行早期周期网络漏洞评估的方法

获取原文

摘要

During development of high assurance cyber systems, third-party security evaluations such as cyber vulnerability assessments (CVAs) and red teaming may not be conducted until after system implementation. This late in the systems development lifecycle (SDLC), mitigating a single implementation vulnerability may require altering the system requirements, architecture, and design, resulting in a cascade of secondary effects that necessitate additional implementation changes. This paper proposes to identify and mitigate vulnerabilities earlier in the SDLC by conducting early-cycle CVAs (eCVAs). eCVAs initiate the vulnerability assessment process earlier and integrate three CVAs into the SDLC. The three types of assessments include a requirements CVA to analyze system requirements specifications, an architecture and design CVA to evaluate architecture and design artifacts, and an implementation CVA with a focus on manual code review, static and dynamic analysis, and researching leveraged code for known vulnerabilities. This paper describes the three types of CVAs and outlines the results of a year-long pilot effort carried out by the Air Force Research Laboratory Information Directorate eCVA team.
机译:在高保证网络系统的发展,如网络脆弱性评估(CVAS)和红队联盟的第三方安全评估之前,将不系统实施后进行。这晚在系统开发生命周期(SDLC),减轻单个实施漏洞可能要求改变系统的要求,体系结构和设计,造成的二次效果是需要额外实现更改的级联。本文提出了通过进行早期循环CVAS(eCVAs)来识别,并在SDLC早期减轻漏洞。 eCVAs启动漏洞评估过程的早期和三个CVAS融入SDLC。这三种类型的评估包括要求CVA分析系统需求规范,架构和设计CVA评价体系结构和设计构件,并侧重于手动代码审查,静态和动态分析的实现CVA,并研究利用代码知漏洞。本文介绍了三种类型的CVAS并概述了美国空军研究实验室信息董事会eCVA队进行了一场长达一年的试点工作的结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号