...
首页> 外文期刊>Requirements Engineering >Eliciting security requirements and tracing them to design: an integration of Common Criteria, heuristics, and UMLsec
【24h】

Eliciting security requirements and tracing them to design: an integration of Common Criteria, heuristics, and UMLsec

机译:提出安全要求并进行跟踪设计:Common Criteria,启发式和UMLsec的集成

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Building secure systems is difficult for many reasons. This paper deals with two of the main challenges: (ⅰ) the lack of security expertise in development teams and (ⅱ) the inadequacy of existing methodologies to support developers who are not security experts. The security standard ISO 14508 Common Criteria (CC) together with secure design techniques such as UMLsec can provide the security expertise, knowledge, and guidelines that are needed. However, security expertise and guidelines are not stated explicitly in the CC. They are rather phrased in security domain terminology and difficult to understand for developers. This means that some general security and secure design expertise are required to fully take advantage of the CC and UMLsec. In addition, there is the problem of tracing security requirements and objectives into solution design, which is needed for proof of requirements fulfilment. This paper describes a security requirements engineering methodology called SecReq. SecReq combines three techniques: the CC, the heuristic requirements editor HeRA, and UMLsec. SecReq makes systematic use of the security engineering knowledge contained in the CC and UMLsec, as well as security-related heuristics in the HeRA tool. The integrated SecReq method supports early detection of security-related issues (HeRA), their systematic refinement guided by the CC, and the ability to trace security requirements into UML design models. A feedback loop helps reusing experience within SecReq and turns the approach into an iterative process for the secure system life-cycle, also in the presence of system evolution.
机译:建立安全系统很困难,原因有很多。本文解决了两个主要挑战:(ⅰ)开发团队中缺乏安全专业知识;(ⅱ)现有方法不足以支持非安全专家的开发人员。安全标准ISO 14508通用标准(CC)以及诸如UMLsec之类的安全设计技术可以提供所需的安全专业知识,知识和准则。但是,CC中未明确说明安全专业知识和准则。它们用安全域术语表述,对于开发人员来说很难理解。这意味着要充分利用CC和UMLsec,需要一些常规的安全性和安全设计专业知识。此外,还存在将安全需求和目标追踪到解决方案设计中的问题,这是证明满足需求的必要条件。本文介绍了一种称为SecReq的安全需求工程方法。 SecReq结合了三种技术:CC,启发式需求编辑器HeRA和UMLsec。 SecReq系统地利用了CC和UMLsec中包含的安全工程知识以及HeRA工具中与安全相关的启发式方法。集成的SecReq方法支持对安全性相关问题(HeRA)的早期检测,在CC的指导下对其进行系统化完善以及将安全性需求跟踪到UML设计模型中的能力。反馈循环有助于在SecReq中重用经验,并且即使存在系统演进过程,也将方法转变为安全系统生命周期的迭代过程。

著录项

  • 来源
    《Requirements Engineering》 |2010年第1期|63-93|共31页
  • 作者单位

    Connected Objects Laboratory, Service Platform Group,Telenor GBDR, Otto Nielsens vei 12, 7004 Trondheim, Norway;

    Fakultaet fuer Informatik, Technische Universitaet Muenchen,Boltzmannstr. 3, 85748 Garching, Germany;

    Software Engineering Group, Leibniz Universitaet Hannover,Welfengarten 1, 30167 Hannover, Germany;

    Software Engineering(14), Technische Universitaet Dortmund, Baroper Strasse 301, 44227 Dortmund, Germany;

    Software Engineering Group, Leibniz Universitaet Hannover,Welfengarten 1, 30167 Hannover, Germany;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    security requirement elicitation; common criteria (CC); UMLsec; heuristics; secure design;

    机译:安全需求引发;通用标准(CC);UMLsec;启发式安全设计;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号