首页> 美国卫生研究院文献>Journal of Advanced Research >Capturing security requirements for software systems
【2h】

Capturing security requirements for software systems

机译:捕获软件系统的安全性要求

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Security is often an afterthought during software development. Realizing security early, especially in the requirement phase, is important so that security problems can be tackled early enough before going further in the process and avoid rework. A more effective approach for security requirement engineering is needed to provide a more systematic way for eliciting adequate security requirements. This paper proposes a methodology for security requirement elicitation based on problem frames. The methodology aims at early integration of security with software development. The main goal of the methodology is to assist developers elicit adequate security requirements in a more systematic way during the requirement engineering process. A security catalog, based on the problem frames, is constructed in order to help identifying security requirements with the aid of previous security knowledge. Abuse frames are used to model threats while security problem frames are used to model security requirements. We have made use of evaluation criteria to evaluate the resulting security requirements concentrating on conflicts identification among requirements. We have shown that more complete security requirements can be elicited by such methodology in addition to the assistance offered to developers to elicit security requirements in a more systematic way.
机译:安全通常是软件开发过程中的事后考虑。尽早实现安全性,尤其是在需求阶段,这一点很重要,这样就可以在进一步进行过程之前及早解决安全问题,并避免返工。需要一种更有效的安全需求工程方法,以提供一种系统的方法来引发足够的安全需求。本文提出了一种基于问题框架的安全需求获取方法。该方法旨在安全性与软件开发的早期集成。该方法的主要目标是帮助开发人员在需求工程过程中以更加系统的方式得出足够的安全需求。基于问题框架构建安全目录,以帮助借助先前的安全知识来识别安全要求。滥用框架用于对威胁进行建模,而安全问题框架用于对安全要求进行建模。我们利用评估标准来评估由此产生的安全性需求,重点是在需求之间进行冲突识别。我们已经表明,除了为开发人员提供帮助以更系统的方式得出安全性要求之外,这种方法还可以引发更完整的安全性要求。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号