首页> 外文期刊>Data & Knowledge Engineering >Ontology-driven evolution of software security
【24h】

Ontology-driven evolution of software security

机译:Ontology驱动的软件安全的演化

获取原文
获取原文并翻译 | 示例
           

摘要

Ontologies as a means to formally specify the knowledge of a domain of interest have made their way into information and communication technology. Most often, such knowledge is subject to continuous change, which demands for consistent evolution of ontologies and dependent artifacts. In this article, we study ontology evolution in the context of software security, where ontologies may be used to formalize the security context knowledge which is needed to properly implement security requirements. In this application scenario, techniques for detecting ontology changes and determining their semantic impact are required to maintain the security of a software-intensive system in response to changing security context knowledge. Our solution is capable of detecting semantic editing patterns, which may be customly defined using graph transformation rules, but it does not depend on information about editing processes such as persistently managed changelogs. We leverage semantic editing patterns for (i) generating system co-evolution proposals, (ii) adapting the configuration of standard security checks, and (iii) performing incremental security compliance analyses between co-evolved system models and the implementation. We demonstrate the feasibility of the approach using a realistic medical information system known as iTrust.
机译:本体作为一种正式指定利益领域的知识的手段使其进入信息和通信技术。大多数情况下,这些知识受到连续变化的影响,要求在本体和依赖文物的一致演变。在本文中,我们在软件安全性的背景下研究本体演变,其中本地可用于正式确定正确实施安全要求所需的安全上下文知识。在本申请方案中,需要检测本体文明变化和确定其语义影响的技术来保持软件密集型系统的安全性,以响应不断变化的安全性上下文知识。我们的解决方案能够检测语义编辑模式,可以使用图形转换规则定制定义,但它不依赖于有关编辑过程的信息,例如持久管理的更改日志。我们利用(i)生成系统共同演进提案的语义编辑模式,(ii)调整标准安全检查的配置,(iii)在共同演化的系统模型和实现之间执行增量安全合规性分析。我们展示了使用称为Itrust的现实医疗信息系统的方法的可行性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号