...
首页> 外文期刊>MATEC Web of Conferences >Knowledge Base for an Intelligent System in order to Identify Security Requirements for Government Agencies Software Projects
【24h】

Knowledge Base for an Intelligent System in order to Identify Security Requirements for Government Agencies Software Projects

机译:智能系统的知识库,以确定政府机构软件项目的安全要求

获取原文
           

摘要

It has been evidenced that one of the most common causes in the failure of software security is the lack of identification and specification of requirements for information security, it is an activity with an insufficient importance in the software development or software acquisition We propose the knowledge base of CIBERREQ. CIBERREQ is an intelligent knowledge-based system used for the identification and specification of security requirements in the software development cycle or in the software acquisition. CIBERREQ receives functional software requirements written in natural language and produces non-functional security requirements through a semi-automatic process of risk management. The knowledge base built is formed by an ontology developed collaboratively by experts in information security. In this process has been identified six types of assets: electronic data, physical data, hardware, software, person and service; as well as six types of risk: competitive disadvantage, loss of credibility, economic risks, strategic risks, operational risks and legal sanctions. In addition there are defined 95 vulnerabilities, 24 threats, 230 controls, and 515 associations between concepts. Additionally, automatic expansion was used with Wikipedia for the asset types Software and Hardware, obtaining 7125 and 5894 software and hardware subtypes respectively, achieving thereby an improvement of 10% in the identification of the information assets candidates, one of the most important phases of the proposed system.
机译:有人证明,软件安全失败的最常见原因之一是缺乏信息安全要求的识别和规范,它是一种在软件开发或软件采集中不充分的活动,我们提出了知识库Ciberreq。 CiberReq是一种基于智能知识的系统,用于识别和规范软件开发周期或软件采集中的安全要求。 CiberReq通过自然语言编写的功能软件要求,通过半自动风险管理产生非功能安全要求。所构建的知识库由信息安全专家协同开发的本体形成。在此过程中已被确定为六种类型的资产:电子数据,物理数据,硬件,软件,人员和服务;以及六种风险:竞争劣势,信誉丧失,经济风险,战略风险,运营风险和法律制裁。此外,定义了95个漏洞,24个威胁,230个控件和515个概念之间的关联。此外,自动扩展与维基百科有用于资产类型软件和硬件,分别获得7125和5894软件和硬件亚型,从而在信息资产候选人的识别中实现了10%的增长,其中最重要的阶段之一提出的系统。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号