首页> 外文会议>IEEE International Requirements Engineering Conference Workshops >Systematically Developing Prevention, Detection, and Response Patterns for Security Requirements
【24h】

Systematically Developing Prevention, Detection, and Response Patterns for Security Requirements

机译:用于安全要求的系统地开发预防,检测和响应模式

获取原文

摘要

The security community has established a number of knowledge sources, including security catalogues and controls, that capture security expertise and can support elicitation of security requirements. Providing additional guidance on how and when to leverage the security information available in the existing knowledge sources in the context of the given system can support security requirements engineering efforts. The objective of this research is to support analysts in identifying and specifying security requirements by developing and utilizing a systematic process for identifying security requirements patterns from existing knowledge sources. We document our process for systematically analyzing and synthesizing existing knowledge sources to identify a set of security requirements patterns that support a diverse set of security goals. We demonstrate the feasibility of our process by applying it to NIST Special Publication 800-53 to identify 35 security requirements patterns related to preventing, detecting and responding to security breaches. Our patterns can generate a broad set of technical security requirements by instantiating 131 different security requirements templates that are grouped in the 35 patterns. Our patterns capture the security context in which each pattern is applicable and the security-specific problem that is addressed, providing conceptual scaffolding around the knowledge abstracted in the security requirements patterns.
机译:安全社区已建立了许多知识来源,包括安全目录和控制,可捕获安全专业知识,并支持安全要求的阐述。提供关于如何以及何时利用现有知识来源的安全信息的额外指导,在给定系统的上下文中可以支持安全要求工程工作。本研究的目的是通过开发和利用系统过程来支持分析师来识别和指定安全要求,以确定来自现有知识来源的安全要求模式。我们记录我们的流程,以系统地分析和综合现有知识来源,以确定支持各种安全目标的安全要求模式。我们通过将其应用于NIST特殊公开800-53来展示我们进程的可行性,以确定与预防,检测和响应安全漏洞相关的35个安全要求模式。我们的模式可以通过实例化35模式分组的不同安全要求模板来生成广泛的技术安全要求。我们的模式捕获了每个模式适用的安全性上下文以及所解决的安全特定问题,提供了在安全要求模式中抽象的知识周围提供概念性脚手架。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号