首页> 外文会议> >MAPE-SAC: A Framework to Dynamically Manage Security Assurance Cases
【24h】

MAPE-SAC: A Framework to Dynamically Manage Security Assurance Cases

机译:MAPE-SAC:动态管理安全保证案例的框架

获取原文
获取原文并翻译 | 示例

摘要

Assuring security compliance in self-adaptive systems is challenging, notably as both functional and security conditions may change at run time, where adaptation of functional behavior may violate security requirements or vice versa. In traditional systems, certification is performed at design time on the mechanisms that will be deployed to guarantee the effectiveness of organizationally chosen and instantiated security controls defined by standards bodies (e.g., NIST SP800-53). In contrast, adaptive systems benefit by run-time adaptations for which dynamic certification could be difficult. Confidence in an information system's compliance with security constraints can be expressed using security assurance cases (SACs). Specifically, NIST security controls follow a repeated structure that make them amenable to their specification in terms of SACs. The collection of SACs for the related security controls form a network that can be used to assess the level of the system's compliance through certification-based evidence. Once the system is deployed, environmental and functional uncertainties may require more complex adaptations that include the coordination of functional and security adaptations. This paper introduces the MAPE-SAC control loop and its interaction with the MAPE-K control loop to dynamically manage run-time adaptations in response to changes in functional and security conditions. We illustrate the use of both control loops and their interaction using an example of an autonomous rover responding to a potential security incident.
机译:确保自适应系统中的安全合规性具有挑战性,尤其是功能和安全条件都可能在运行时发生变化时,适应功能行为可能违反安全性要求,反之亦然。在传统系统中,认证是在设计时对将要部署的机制进行的,以保证由标准机构(例如NIST SP800-53)定义的组织选择和实例化的安全控制的有效性。相反,自适应系统受益于运行时自适应,而动态认证可能会很困难。可以使用安全保证案例(SAC)表示对信息系统遵守安全约束的信心。具体来说,NIST安全控制遵循重复的结构,使其可以按照SAC的要求进行规范。用于相关安全控制的SAC的收集形成一个网络,该网络可用于通过基于证书的证据来评估系统的遵从级别。一旦部署了系统,环境和功能的不确定性可能需要更复杂的调整,包括功能和安全调整的协调。本文介绍了MAPE-SAC控制回路及其与MAPE-K控制回路的相互作用,以动态管理运行时适应功能和安全条件变化的情况。我们以对潜在安全事件做出响应的自主漫游车为例,说明了两个控制环的使用及其相互作用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号