首页> 外文期刊>MATEC Web of Conferences >Knowledge Base for an Intelligent System in order to Identify Security Requirements for Government Agencies Software Projects
【24h】

Knowledge Base for an Intelligent System in order to Identify Security Requirements for Government Agencies Software Projects

机译:智能系统的知识库,以确定政府机构软件项目的安全要求

获取原文
           

摘要

It has been evidenced that one of the most common causes in the failure of software security is the lack of identification and specification of requirements for information security, it is an activity with an insufficient importance in the software development or software acquisition We propose the knowledge base of CIBERREQ. CIBERREQ is an intelligent knowledge-based system used for the identification and specification of security requirements in the software development cycle or in the software acquisition. CIBERREQ receives functional software requirements written in natural language and produces non-functional security requirements through a semi-automatic process of risk management. The knowledge base built is formed by an ontology developed collaboratively by experts in information security. In this process has been identified six types of assets: electronic data, physical data, hardware, software, person and service; as well as six types of risk: competitive disadvantage, loss of credibility, economic risks, strategic risks, operational risks and legal sanctions. In addition there are defined 95 vulnerabilities, 24 threats, 230 controls, and 515 associations between concepts. Additionally, automatic expansion was used with Wikipedia for the asset types Software and Hardware, obtaining 7125 and 5894 software and hardware subtypes respectively, achieving thereby an improvement of 10% in the identification of the information assets candidates, one of the most important phases of the proposed system.
机译:已经证明,导致软件安全性失败的最常见原因之一是缺乏对信息安全性要求的识别和规范,这是对软件开发或软件获取不重要的活动。我们提出了知识库CIBERREQ。 CIBERREQ是基于智能知识的系统,用于在软件开发周期或软件购买中识别和指定安全要求。 CIBERREQ接收以自然语言编写的功能性软件需求,并通过半自动的风险管理流程产生非功能性安全需求。建立的知识库由信息安全专家共同开发的本体构成。在此过程中,已确定了六种资产:电子数据,物理数据,硬件,软件,人员和服务;以及六种风险:竞争劣势,信誉丧失,经济风险,战略风险,运营风险和法律制裁。此外,概念之间定义了95个漏洞,24个威胁,230个控件以及515个关联。此外,Wikipedia对资产类型软件和硬件使用自动扩展,分别获得7125和5894软件和硬件子类型,从而将信息资产候选者的识别提高了10%,这是信息资产候选者最重要的阶段之一。建议的系统。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号