...
首页> 外文期刊>International journal of information and computer security >Security engineering methods - in-depth analysis
【24h】

Security engineering methods - in-depth analysis

机译:安全工程方法-深入分析

获取原文
获取原文并翻译 | 示例

摘要

Providing security to complex information system development is challenging because of complex network and ubiquitous system. Traditional mechanisms address security concerns during development or design phases that may lead to various loopholes or over-constrained system. The field of security engineering has emerged whereby security requirements are gathered along with other requirements during the initial phase of software development. However, dealing with security concerns during the initial phases of development is challenging because of design and code unavailability. The paper first represents the proposals for security requirements engineering based on different approaches such as use case approach, goal-oriented approach, and process-oriented approach. These methodologies are evaluated along various parameters such as security engineering activities covered, application domain and others. The in-depth analysis ends with a recent proposal for security engineering and list of unresolved issues that needs consideration. The outcome of the paper can be exploited to drive further research.
机译:由于复杂的网络和普遍存在的系统,为复杂的信息系统开发提供安全性具有挑战性。传统机制解决了开发或设计阶段的安全问题,这可能导致各种漏洞或系统过度受限。安全工程领域已经出现,在软件开发的初始阶段,安全要求与其他要求一起被收集。但是,由于设计和代码不可用,在开发的初始阶段处理安全性问题具有挑战性。本文首先代表基于不同方法(例如用例方法,面向目标的方法和面向过程的方法)的安全需求工程建议。这些方法是根据各种参数进行评估的,例如所涵盖的安全工程活动,应用程序域等。深入的分析以最近针对安全工程的建议和需要考虑的未解决问题列表结尾。可以利用本文的结果来推动进一步的研究。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号