首页> 外文期刊>International journal of software engineering and knowledge engineering >SECURITY REQUIREMENT REPRESENTATION METHOD FOR CONFIDENCE OF SYSTEMS AND NETWORKS
【24h】

SECURITY REQUIREMENT REPRESENTATION METHOD FOR CONFIDENCE OF SYSTEMS AND NETWORKS

机译:系统和网络保密性的安全性要求表示方法

获取原文
获取原文并翻译 | 示例
           

摘要

Software vulnerability is a key determiner of confidence in computer systems and networks. Usually, software requirements are listed at the beginning of software design, whereas vulnerabilities appear only after development is complete and sometimes only after the system is operational. Therefore, the security requirements during the design stage should address software vulnerabilities. This paper presents a method of representing software vulnerabilities as atomic vulnerabilities (AVs): an AV is an undivid-able cause-unit of vulnerability, and a set of AVs and the relationships among them represent software vulnerabilities. The AV concept originates from system theory and modeling methodology. AVs and the relationships among them can be used to construct a behavioral model of systems and networks with a focus on vulnerability. The logical relationships among AVs are named vulnerability expressions (VXs). With all the accumulated VXs of the systems and networks, we can set security requirements that resolve or circumvent vulnerabilities effectively and reinforce confidence in system and network robustness. The contribution of this paper is to use the concepts of AV and VX to derive the security requirements considering software vulnerabilities for secure systems and networks. The requirement derived can be used to complement the vulnerable situation caused by software that is developed without cognizance of security consideration.
机译:软件漏洞是对计算机系统和网络的信心的关键决定因素。通常,软件需求在软件设计之初就列出,而漏洞仅在开发完成后才出现,有时仅在系统运行后才出现。因此,设计阶段的安全要求应解决软件漏洞。本文提出了一种将软件漏洞表示为原子漏洞(AV)的方法:AV是漏洞的不可分割的原因单位,并且一组AV及其之间的关系表示软件漏洞。 AV概念源自系统理论和建模方法。 AV及其之间的关系可用于构建以漏洞为重点的系统和网络的行为模型。 AV之间的逻辑关系称为漏洞表达(VX)。借助系统和网络的所有累积VX,我们可以设置安全要求,以有效解决或规避漏洞并增强对系统和网络健壮性的信心。本文的贡献是使用AV和VX的概念来推导考虑安全系统和网络的软件漏洞的安全要求。导出的需求可用于补充由开发的软件引起的易受攻击的情况,这些软件是在不考虑安全性考虑的情况下开发的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号