首页> 外文期刊>Software Quality Journal >Taxonomy of quality metrics for assessing assurance of security correctness
【24h】

Taxonomy of quality metrics for assessing assurance of security correctness

机译:质量指标分类法,用于评估安全性正确性的保证

获取原文
获取原文并翻译 | 示例
           

摘要

Assurance is commonly considered as "something said or done to inspire confidence" (Webster dictionary). However, the level of confidence inspired from a statement or an action depends on the quality of its source. Similarly, the assurance that the deployed security mechanisms exhibit an appropriate posture depends on the quality of the verification process adopted. This paper presents a novel taxonomy of quality metrics pertinent for gaining assurance in a security verification process. Inspired by the systems security engineering capability maturity model and the common criteria, we introduce five ordinal quality levels for a verification process aimed at probing the correctness of runtime security mechanisms. In addition, we analyse the mapping between the quality levels and different capability levels of the following verification metrics families: coverage, rigour, depth and independence of verification. The quality taxonomy is part of a framework for the Security Assurance of operational systems. These metrics can also be used for gaining assurance in other areas such as legal and safety compliance. Furthermore, the resulting metrics taxonomy could, by identifying appropriate quality security requirements, assist manufacturers of information technology (IT) in developing their products or systems. Additionally, the taxonomy could also empower consumers in IT security product selection to efficaciously and effectively match their organisational needs, while IT security eval-uators can use it as a reference point when forming judgments about the quality of a security product. We demonstrate the applicability of the proposed taxonomy through access control examples.
机译:保证通常被认为是“说过或做过的事情以激发信心”(韦伯斯特词典)。但是,声明或行动所激发的信心水平取决于其来源的质量。同样,确保已部署的安全机制表现出适当的状态取决于所采用的验证过程的质量。本文提出了一种新颖的质量指标分类法,旨在在安全验证过程中获得保证。受系统安全工程能力成熟度模型和通用标准的启发,我们为验证过程引入了五个序数质量级别,旨在检验运行时安全机制的正确性。此外,我们分析了以下验证指标系列的质量级别和不同功能级别之间的映射:验证的覆盖范围,严谨性,深度和独立性。质量分类法是操作系统安全保证框架的一部分。这些度量标准还可用于在其他领域(例如法律和安全合规性)中获得保证。此外,通过确定适当的质量安全要求,得出的度量标准分类法可以帮助信息技术(IT)制造商开发其产品或系统。此外,分类法还可以使消费者选择IT安全产品来有效,有效地满足他们的组织需求,而IT安全评估人员可以在确定安全产品质量时将其用作参考点。我们通过访问控制示例演示了拟议分类法的适用性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号