首页> 外文期刊>The Journal of Systems and Software >A framework for semi-automated co-evolution of security knowledge and system models
【24h】

A framework for semi-automated co-evolution of security knowledge and system models

机译:半自动化安全知识和系统模型协同进化的框架

获取原文
获取原文并翻译 | 示例
       

摘要

Security is an important and challenging quality aspect of software-intensive systems, becoming even more demanding regarding long-living systems. Novel attacks and changing laws lead to security issues that did not necessarily rise from a flawed initial design, but also when the system fails to keep up with a changing environment. Thus, security requires maintenance throughout the operation phase. Ongoing adaptations in response to changed security knowledge are inevitable. A necessary prerequisite for such adaptations is a good understanding of the security-relevant parts of the system and the security knowledge.We present a model-based framework for supporting the maintenance of security during the long-term evolution of a software system. It uses ontologies to manage the system-specific and the security knowledge. With model queries, graph transformation and differencing techniques, knowledge changes are analyzed and the system model is adapted. We introduce the novel concept ofSecurity Maintenance Rulesto couple the evolution of security knowledge with co-evolutions of the system model.As evaluation, community knowledge about vulnerabilities is used (Common Weakness Enumeration database). We show the applicability of the framework to theiTrustsystem from the medical care domain and hence show the benefits of supporting co-evolution for maintaining secure systems.
机译:安全性是软件密集型系统的重要且具有挑战性的质量方面,对长期使用的系统的要求变得更高。新颖的攻击和不断变化的法律会导致安全问题,而安全问题并不一定源于有缺陷的初始设计,而且还可能源于系统无法适应不断变化的环境。因此,安全性需要在整个操作阶段进行维护。为响应不断变化的安全性知识而进行的不断调整是不可避免的。进行此类修改的必要先决条件是对系统中与安全性相关的部分以及安全性知识的充分理解。我们提出了一种基于模型的框架,用于在软件系统的长期演进过程中支持安全性的维护。它使用本体来管理特定于系统的知识和安全知识。通过模型查询,图形转换和微分技术,可以分析知识变化并调整系统模型。我们引入了安全维护规则的新颖概念,将安全知识的发展与系统模型的协同演化结合在一起。作为评估,使用了有关漏洞的社区知识(通用弱点枚举数据库)。我们展示了该框架从医疗保健领域到iTrustsystem的适用性,因此展示了支持协同进化以维护安全系统的好处。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号