首页> 外文会议>IEEE International Workshops on Foundations and Applications of Self* Systems >MAPE-SAC: A Framework to Dynamically Manage Security Assurance Cases
【24h】

MAPE-SAC: A Framework to Dynamically Manage Security Assurance Cases

机译:mape-sac:动态管理安全保障案件的框架

获取原文

摘要

Assuring security compliance in self-adaptive systems is challenging, notably as both functional and security conditions may change at run time, where adaptation of functional behavior may violate security requirements or vice versa. In traditional systems, certification is performed at design time on the mechanisms that will be deployed to guarantee the effectiveness of organizationally chosen and instantiated security controls defined by standards bodies (e.g., NIST SP800-53). In contrast, adaptive systems benefit by run-time adaptations for which dynamic certification could be difficult. Confidence in an information system's compliance with security constraints can be expressed using security assurance cases (SACs). Specifically, NIST security controls follow a repeated structure that make them amenable to their specification in terms of SACs. The collection of SACs for the related security controls form a network that can be used to assess the level of the system's compliance through certification-based evidence. Once the system is deployed, environmental and functional uncertainties may require more complex adaptations that include the coordination of functional and security adaptations. This paper introduces the MAPE-SAC control loop and its interaction with the MAPE-K control loop to dynamically manage run-time adaptations in response to changes in functional and security conditions. We illustrate the use of both control loops and their interaction using an example of an autonomous rover responding to a potential security incident.
机译:在自适应系统确保安全合规性是具有挑战性的,尤其是作为兼具功能性和安全条件可能会在运行时,其中的功能行为适应可能违反安全要求,或反之亦然。在传统系统中,认证在设计时间上进行了将部署的机制,以保证由标准机构定义的组织所选择和实例化安全控制的有效性(例如,NIST SP800-53)。相比之下,自适应系统受到动态认证可能困难的运行时的适应性。可以使用安全保障案例(SACS)表达对信息系统的信心与安全约束的遵守。具体而言,NIST安全控制遵循重复的结构,使其在囊方面使其适用于其规范。相关安全控制的SAC的集合形成了一种可用于通过基于证书的证据来评估系统遵从性的网络。一旦系统部署,环境和功能不确定性可能需要更复杂的适应,包括功能和安全自适应的协调。本文介绍了MAPE-SAC控制回路及其与MAPE-K控制循环的交互,以响应于功能和安全条件的变化而动态管理运行时调整。我们说明了使用控制循环和它们的交互的使用,使用自主流动站响应潜在的安全事件的示例。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号