首页> 外文学位 >Requirements-based access control analysis and policy specification.
【24h】

Requirements-based access control analysis and policy specification.

机译:基于需求的访问控制分析和策略规范。

获取原文
获取原文并翻译 | 示例

摘要

Access control is a mechanism for achieving confidentiality and integrity in software systems. Access control policies (ACPs) define how access is managed and the high-level rules of who can access what information under certain conditions. Traditionally, access control policies have been specified in an ad-hoc manner, leaving systems vulnerable to security breaches. ACP specification is often isolated from requirements analysis, resulting in policies that are not in compliance with system requirements. This dissertation introduces the Requirements-based Access C&barbelow;ontrol A&barbelow;nalysis and P&barbelow;olicy S&barbelow;pecification (ReCAPS) method for deriving access control policies from various sources, including software requirements specifications (SRS), software designs, and high-level security/privacy policies. The ReCAPS method is essentially an analysis method supported by a set of heuristics and a software tool: the Security and Privacy Requirements Analysis Tool (SPRAT). The method was developed in two formative case studies and validated in two summative case studies. All four case studies involved operational systems, and ReCAPS evolved as a result of the lessons learned from applying the method to these case studies. Further validation of the method was performed via an empirical study to evaluate the usefulness and effectiveness of the approach. Results from these evaluations indicate that the process and heuristics provided by the ReCAPS method are useful for specifying database-level and application-level ACPs. Additionally, ReCAPS integrates policy specification into software development, thus providing a basic framework for ensuring compliance between different levels of policies, system requirements and software design. The method also improves the quality of requirements specifications and system designs by clarifying ambiguities and resolving conflicts across these artifacts.
机译:访问控制是一种用于在软件系统中实现机密性和完整性的机制。访问控制策略(ACP)定义访问的管理方式以及在特定条件下谁可以访问哪些信息的高级规则。传统上,访问控制策略是临时指定的,使系统容易受到安全漏洞的攻击。 ACP规范通常与需求分析隔离开,从而导致策略不符合系统需求。本文介绍了基于需求的访问控制策略和策略规范化(ReCAPS)方法,该方法可从各种需求中获取访问控制策略,包括软件需求规范(SRS),软件设计和高层安全性。 /隐私权政策。 ReCAPS方法实质上是一种分析方法,由一组试探法和一个软件工具(安全和隐私要求分析工具(SPRAT))支持。该方法是在两个形成性案例研究中开发的,并在两个总结性案例研究中得到了验证。所有四个案例研究都涉及操作系统,ReCAPS的发展是从将方法应用于这些案例研究中学到的教训。通过经验研究对该方法进行了进一步验证,以评估该方法的有效性和有效性。这些评估的结果表明,ReCAPS方法提供的过程和启发式方法对于指定数据库级别和应用程序级别的ACP很有用。此外,ReCAPS将策略规范集成到软件开发中,从而为确保不同级别的策略,系统要求和软件设计之间的合规性提供了基本框架。该方法还通过澄清歧义并解决这些工件之间的冲突,从而提高了需求规范和系统设计的质量。

著录项

  • 作者

    He, Qingfeng.;

  • 作者单位

    North Carolina State University.;

  • 授予单位 North Carolina State University.;
  • 学科 Computer Science.
  • 学位 Ph.D.
  • 年度 2005
  • 页码 256 p.
  • 总页数 256
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 自动化技术、计算机技术;
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号