首页> 外文期刊>Information and software technology >Requirements-based Access Control Analysis And Policy Specification (recaps)
【24h】

Requirements-based Access Control Analysis And Policy Specification (recaps)

机译:基于需求的访问控制分析和策略规范(摘要)

获取原文
获取原文并翻译 | 示例
           

摘要

Access control (AC) is a mechanism for achieving confidentiality and integrity in software systems. Access control policies (ACPs) express rules concerning who can access what information, and under what conditions. ACP specification is not an explicit part of the software development process and is often isolated from requirements analysis activities, leaving systems vulnerable to security breaches because policies are specified without ensuring compliance with system requirements. In this paper, we present the Requirements-based Access Control Analysis and Policy Specification (ReCAPS) method for deriving and specifying ACPs, and discuss three validation efforts. The method integrates policy specification into the software development process, ensures consistency across software artifacts, and provides prescriptive guidance for how to specify ACPs. It also improves the quality of requirements specifications and system designs by clarifying ambiguities and resolving conflicts across these artifacts during the analysis, making a significant step towards ensuring that policies are enforced in a manner consistent with a system's requirements specifications. To date, the method has been applied within the context of four operational systems. Additionally, we have conducted an empirical study to evaluate its usefulness and effectiveness. A software tool, the Security and Privacy Requirements Analysis Tool (SPRAT), was developed to support ReCAPS analysis activities.
机译:访问控制(AC)是一种用于在软件系统中实现机密性和完整性的机制。访问控制策略(ACP)表达了有关谁可以在什么条件下访问哪些信息的规则。 ACP规范不是软件开发过程的明确组成部分,并且通常与需求分析活动隔离开来,使系统容易遭受安全漏洞,因为在未确保符合系统要求的情况下指定了策略。在本文中,我们提出了用于导出和指定ACP的基于需求的访问控制分析和策略规范(ReCAPS)方法,并讨论了三项验证工作。该方法将策略规范集成到软件开发过程中,确保各个软件工件之间的一致性,并为如何指定ACP提供规范指导。通过在分析过程中澄清歧义并解决这些工件之间的冲突,它还提高了需求规范和系统设计的质量,为确保以与系统需求规范一致的方式执行策略迈出了重要一步。迄今为止,该方法已在四个操作系统中应用。此外,我们进行了一项实证研究,以评估其有效性和有效性。开发了一种软件工具,即安全和隐私要求分析工具(SPRAT),以支持ReCAPS分析活动。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号