首页> 外文会议>IEEE/ACM International Symposium on Software Engineering for Adaptive and Self-Managing Systems >Toward Evaluating the Impact of Self-Adaptation on Security Control Certification
【24h】

Toward Evaluating the Impact of Self-Adaptation on Security Control Certification

机译:在评估自适应对安全控制认证的影响

获取原文

摘要

Certifying security controls is required for information systems that are either federally maintained or maintained by a US government contractor. As described in the NIST SP800-53, certified and accredited information systems are deployed with an acceptable security threat risk. Self-adaptive information systems that allow functional and decision-making changes to be dynamically configured at runtime may violate security controls increasing the risk of security threat to the system. Methods are needed to formalize the process of certification for security controls by expressing and verifying the functional and non-functional requirements to determine what risks are introduced through self-adaptation. We formally express the existence and behavior requirements of the mechanisms needed to guarantee the security controls' effectiveness using audit controls on program example. To reason over the risk of security control compliance given runtime self-adaptations, we use the KIV theorem prover on the functional requirements, extracting the verification concerns and workflow associated with the proof process. We augment the MAPE-K control loop planner with knowledge of the mechanisms that satisfy the existence criteria expressed by the security controls. We compare self-adaptive plans to assess their risk of security control violation prior to plan deployment.
机译:通过美国政府承包商联邦维持或维护的信息系统需要认证安全控制。如NIST SP800-53中所述,通过可接受的安全威胁风险部署认证和认可的信息系统。允许在运行时动态配置功能和决策更改的自适应信息系统可能会违反安全控制,从而提高安全威胁对系统的风险。需要通过表达和验证功能和非功能要求来确定安全控制认证过程,以确定通过自适应引入的风险。我们正式表达了在程序示例上使用审核控制所需的机制所需的机制所需的存在和行为要求。通过对运行时自适应的安全控制顺应性的风险,我们在功能要求上使用KIV定理箴言,提取与证明过程相关的验证问题和工作流程。我们增强了MAPE-K控制回路计划,了解满足安全控制表达的存在标准的机制。我们比较自适应计划在计划部署之前评估其安全控制违规风险。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号