首页> 外文学位 >Combining multiple perspectives in the specification of a security assessment methodology.
【24h】

Combining multiple perspectives in the specification of a security assessment methodology.

机译:在安全评估方法的规范中结合了多种观点。

获取原文
获取原文并翻译 | 示例

摘要

This dissertation describes a methodology to assess computer system security based on evaluations from three complementary perspectives: requirements and specifications, system attributes, and experimentation. The underlying evaluations lead to the development and modification of Bayesian Belief Network models which incorporate mechanisms to accommodate “out-of-model” breaches in security that may be observed from experience with actual systems.; The three perspectives incorporated in the Multiple Perspective Security Assessment Methodology (MPSAM) were selected because they provide complementary views defining system behavior. The initial system designers view the system as a collection of requirements and specifications and need to be able to perform some early analyses to estimate the expected security. Potential system users may additionally consider attributes describing the environment and context for the system, such as distribution and age, to provide some indication of the expected system security based on historical information provided from similarly classified systems. The assessments made from these initial two perspectives will frequently be refined as a result of experience with the system or from experimentation to emulate the actions of an attacker on actual systems to improve the estimates of either crossing or circumventing the security barriers in the system. MPSAM provides a framework for an integrated assessment of system security and is intended to be open to modification if additional perspectives are identified.
机译:本文从需求和规格,系统属性和实验三个互补的角度介绍了一种基于评估的计算机系统安全评估方法。基本评估导致了贝叶斯信任网络模型的开发和修改,该模型合并了一些机制,以适应实际系统中可能发现的安全性“模型外”漏洞。选择了包含在多视角安全评估方法(MPSAM)中的三个视角,因为它们提供了定义系统行为的互补视角。最初的系统设计人员将系统视为需求和规格的集合,并且需要能够执行一些早期分析以估计预期的安全性。潜在的系统用户可以另外考虑描述系统环境和上下文的属性(例如分布和使用年限),以根据从类似分类的系统提供的历史信息提供对预期系统安全性的某种指示。从这最初的两个角度进行的评估通常会根据系统的经验或通过模拟攻击者在实际系统上的行为以提高对越过或规避系统中安全屏障的估计的经验而进行完善。 MPSAM提供了一个用于系统安全性综合评估的框架,如果发现其他观点,则可以进行修改。

著录项

  • 作者

    Salinas, Maximo Hans.;

  • 作者单位

    University of Virginia.;

  • 授予单位 University of Virginia.;
  • 学科 Engineering Electronics and Electrical.; Computer Science.
  • 学位 Ph.D.
  • 年度 2003
  • 页码 p.1414
  • 总页数 132
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 无线电电子学、电信技术;
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号