...
首页> 外文期刊>American journal of applied sciences >Security Policy Development: Towards a Life-Cycle and Logic-Based Verification Model | Science Publications
【24h】

Security Policy Development: Towards a Life-Cycle and Logic-Based Verification Model | Science Publications

机译:安全策略开发:建立生命周期和基于逻辑的验证模型科学出版物

获取原文
           

摘要

> Although security plays a major role in the design of software systems, security requirements and policies are usually added to an already existing system, not created in conjunction with the product. As a result, there are often numerous problems with the overall design. In this paper, we discuss the relationship between software engineering, security engineering, and policy engineering and present a security policy life-cycle; an engineering methodology to policy development in high assurance computer systems. The model provides system security managers with a procedural engineering process to develop security policies. We also present an executable Prolog-based model as a formal specification and knowledge representation method using a theorem prover to verify system correctness with respect to security policies in their life-cycle stages.
机译: >尽管安全性在软件系统的设计中起着主要作用,但是安全性要求和策略通常会添加到已经存在的系统中,而不是与产品一起创建。结果,总体设计经常存在许多问题。在本文中,我们讨论了软件工程,安全工程和策略工程之间的关系,并提出了安全策略生命周期。在高保证计算机系统中制定政策的工程方法学。该模型为系统安全管理人员提供了一个程序工程流程来开发安全策略。我们还提出了一个基于Prolog的可执行模型,作为正式的规范和知识表示方法,使用定理证明器来验证系统在生命周期阶段相对于安全策略的正确性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号