...
首页> 外文期刊>Data & Knowledge Engineering >Modeling and analysis of security trade-offs - A goal oriented approach
【24h】

Modeling and analysis of security trade-offs - A goal oriented approach

机译:安全权衡的建模和分析-面向目标的方法

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

In designing software systems, security is typically only one design objective among many. It may compete with other objectives such as functionality, usability, and performance. Too often, security mechanisms such as firewalls, access control, or encryption are adopted without explicit recognition of competing design objectives and their origins in stakeholders' interests. Recently, there is increasing acknowledgement that security is ultimately about trade-offs. One can only aim for "good enough" security, given the competing demands from many parties. This paper investigates the criteria for a conceptual modeling technique for making security trade-offs. We examine how conceptual modeling can provide explicit and systematic support for modeling and analyzing security trade-offs. We examine several existing approaches for dealing with trade-offs and security trade-offs in particular. From analyzing the limitations of existing methods, we propose an extension to the i* Framework for security trade-off analysis, taking advantage of its multi-agent and goal orientation. The method was applied to several case studies used to exemplify existing approaches. The resulting models developed using different approaches are compared.
机译:在设计软件系统时,安全性通常只是众多设计目标之一。它可能会与其他目标竞争,例如功能,可用性和性能。常常采用安全机制(例如防火墙,访问控制或加密),而没有明确认识竞争设计目标及其利益相关者的利益。最近,越来越多的人意识到安全性最终是要权衡的。鉴于许多方面的竞争需求,人们只能争取“足够好”的安全性。本文研究了进行安全权衡的概念建模技术的标准。我们研究了概念建模如何为建模和分析安全性折衷提供明确和系统的支持。我们研究了几种现有的处理权衡和安全权衡的方法。通过分析现有方法的局限性,我们提出了i *框架的扩展,以利用其多主体和目标导向的优势进行安全性折衷分析。该方法已应用于几个案例研究中,这些案例例证了现有方法。比较使用不同方法开发的结果模型。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号