【24h】

Model based risk management of security critical systems

机译:基于模型的安全关键系统的风险管理

获取原文
获取原文并翻译 | 示例

摘要

This paper describes a novel framework for a risk management process involving a model-based approach, developed as the main objective of CORAS (IST-2000 25031). The main motivation for this approach is to achieve an improved methodology for precise, unambiguous, and efficient risk analysis of security critical systems. There are several benefits from a model-based approach. Firstly, the description of the target system, its context and all security relevant features required for risk analysis, can be improved by applying state-of-the-art modelling technology. Secondly, it provides a rich set of graphical descriptions that address properties of the target system as well as their context (including the behaviour of humans), which improves communication and interaction between stakeholders involved in a risk analysis and also facilitates the formalization of threats and more precise documentation of risk analysis results and the assumptions. Finally, tighter integration of risk management in the system development process may considerably reduce the development costs. In this paper we place the emphasis on the proposed guidelines and recommendations for model-based risk management, which will be evaluated through trials in the e-commerce and telemedicine areas. Since CORAS is an ongoing project, the research described here is work in progress.
机译:本文介绍了一种风险管理流程的新颖框架,其中涉及基于模型的方法,该方法已开发为CORAS的主要目标(IST-2000 25031)。这种方法的主要动机是实现一种改进的方法,以对安全关键系统进行精确,明确和有效的风险分析。基于模型的方法有很多好处。首先,可以通过应用最新的建模技术来改进目标系统的描述,其上下文以及风险分析所需的所有与安全相关的功能。其次,它提供了一组丰富的图形描述,这些图形描述涉及目标系统的属性及其上下文(包括人类行为),从而改善了参与风险分析的利益相关者之间的沟通和互动,也促进了威胁和威胁的形式化。更准确地记录风险分析结果和假设。最后,在系统开发过程中紧密集成风险管理可以大大降低开发成本。在本文中,我们将重点放在基于模型的风险管理的建议指南和建议上,这些指南和建议将通过在电子商务和远程医疗领域中的试验进行评估。由于CORAS是一个正在进行的项目,因此此处描述的研究正在进行中。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号