首页> 外文会议>Microwave Symposium Digest, 2005 >Analyzing information flow control policies in requirements engineering
【24h】

Analyzing information flow control policies in requirements engineering

机译:分析需求工程中的信息流控制策略

获取原文
获取原文并翻译 | 示例

摘要

Currently security features are implemented and validated during the last phases of the software development life cycle. This practice results in less secure software systems and higher cost of fixing defects software vulnerability. To achieve more secure systems, security features must be considered during the early phases of the software development process. This work presents a high-level methodology that analyzes the information flow requirements and ensures the proper enforcement of information flow control policies. The methodology uses requirements specified in the Unified Modeling Language (UML) as its input and stratified logic programming language as the analysis language. The methodology improves security by detecting unsafe information flows before proceeding to latter stages of the life cycle.
机译:当前,安全功能是在软件开发生命周期的最后阶段实施和验证的。这种做法导致软件系统的安全性降低,并且修复缺陷软件漏洞的成本更高。为了获得更安全的系统,必须在软件开发过程的早期阶段考虑安全功能。这项工作提出了一种高级方法,可以分析信息流需求并确保信息流控制策略的正确实施。该方法使用统一建模语言(UML)中指定的要求作为其输入,并使用分层逻辑编程语言作为分析语言。该方法通过在进入生命周期的后期之前检测不安全的信息流来提高安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号