...
首页> 外文期刊>Requirements Engineering >Automating trade-off analysis of security requirements
【24h】

Automating trade-off analysis of security requirements

机译:自动权衡安全需求

获取原文
获取原文并翻译 | 示例

摘要

A key aspect of engineering secure systems is identifying adequate security requirements to protect critical assets from harm. However, security requirements may compete with other requirements such as cost and usability. For this reason, they may only be satisfied partially and must be traded off against other requirements to achieve "good-enough security". This paper proposes a novel approach to automate security requirements analysis in order to determine maximum achievable satisfaction level for security requirements and identify trade-offs between security and other requirements. We also propose a pruning algorithm to reduce the search space size in the analysis. We represent security concerns and requirements using asset, threat, and goal models, initially proposed in our previous work. To deal with uncertainty and partial requirements, satisfaction security concerns are quantified by leveraging the notion of composite indicators, which are computed through metric functions based on range normalisation. An SMT solver (Z3) interprets the models and automates the execution of our analyses. We illustrate and evaluate our approach by applying it to a substantive example of a service-based application for exchanging emails.
机译:工程安全系统的一个关键方面是确定适当的安全要求,以保护关键资产免受损害。但是,安全性要求可能会与其他要求(例如成本和可用性)竞争。因此,它们只能部分满足,并且必须权衡其他要求以实现“足够好的安全性”。本文提出了一种自动进行安全需求分析的新颖方法,以确定对安全需求的最大可满足水平,并确定安全与其他需求之间的权衡。我们还提出了一种修剪算法,以减少分析中的搜索空间大小。我们使用资产,威胁和目标模型来表示安全问题和需求,这些模型是我们先前工作中最初提出的。为了处理不确定性和部分需求,可以通过利用基于范围归一化的度量函数计算的综合指标的概念来量化满意度安全问题。 SMT求解器(Z3)解释模型并自动执行我们的分析。我们通过将其应用于交换邮件的基于服务的应用程序的一个实质性示例来说明和评估我们的方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号