首页> 外文会议>Security, privacy, and anonymity in computation, communication, and storage >A Systematic Mapping Study on Security Requirements Engineering Frameworks for Cyber-Physical Systems
【24h】

A Systematic Mapping Study on Security Requirements Engineering Frameworks for Cyber-Physical Systems

机译:网络物理系统安全需求工程框架的系统映射研究

获取原文
获取原文并翻译 | 示例

摘要

Since the world is moving towards secure systems which makes security a primary concern and not an afterthought in software development. Secure software development involves security at each step of development lifecycle from requirements phase to testing. With surging focus on security requirements, we can see an increase in frameworks/methods/techniques proposed to deal with security requirements for variable applications. However, to summarise the literature findings till date and to propose further ways to handle security requirements a systematic and comprehensive review is needed. Our objective is to conduct a systematic mapping study for cyber-physical systems: (ⅰ) to explore and analyse security requirements engineering frameworks/ methods/techniques proposed till date, (ⅱ) to investigate on their strengths and weaknesses, and (ⅲ) to determine the security threats and requirements reported in literature. We conducted a systematic mapping study for which we defined our goals and determined research questions, denned inclusion/exclusion criteria, and designed the map systematically based on the research questions. The search yielded 337 articles after deploying the query on multiple databases and refining the search iteratively through a multistep process. The mapping study identified and categorised the existing security requirements engineering frameworks/methods/techniques focused on their implementation and evaluation mechanisms. Second, we identified and categorised the proposed to deal with security requirements for multiple domains, determined their strengths/weaknesses, and also security requirements and threats reports in the selected studies. The study provides an overall view of the state-of-the-art frameworks/methods/techniques proposed till date to deal with security requirements. The results of this study provide insights to researchers to focus more on developing frameworks to deal with security requirements for particular kinds of systems like cyber-physical systems. Also, it motivates future work to devise methods to cater domain specific security risks and requirements.
机译:由于世界正朝着使安全成为首要考虑因素而不是软件开发事后考虑的安全系统发展。从需求阶段到测试,安全软件开发在开发生命周期的每个步骤都涉及安全性。随着人们对安全性要求的关注日益增加,我们可以看到为应对可变应用程序的安全性要求而提出的框架/方法/技术的增长。但是,要总结迄今为止的文献发现并提出进一步的方法来处理安全性要求,需要进行系统而全面的审查。我们的目标是对网络物理系统进行系统的制图研究:(ⅰ)探索和分析迄今为止提出的安全需求工程框架/方法/技术;(ⅱ)研究其优缺点;以及(and)确定文献中报告的安全威胁和要求。我们进行了系统的制图研究,确定了我们的目标并确定了研究问题,确定了纳入/排除标准,并根据研究问题系统地设计了地图。在将查询部署到多个数据库并通过多步过程反复完善搜索之后,该搜索产生了337篇文章。制图研究确定并分类了现有的安全需求工程框架/方法/技术,重点放在其实施和评估机制上。其次,我们对提议的内容进行了识别和分类,以处理多个域的安全要求,确定了它们的优势/劣势,以及选定研究中的安全要求和威胁报告。该研究报告提供了迄今为止为解决安全性要求而提出的最新框架/方法/技术的整体视图。这项研究的结果为研究人员提供了见识,使他们可以将更多精力放在开发框架上,以应对特定种类系统(如网络物理系统)的安全性要求。而且,它激发了未来的工作,以设计方法来满足特定于域的安全风险和要求。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号