首页> 外文期刊>Software and systems modeling >Holistic security requirements analysis for socio-technical systems
【24h】

Holistic security requirements analysis for socio-technical systems

机译:社会技术系统的整体安全需求分析

获取原文
获取原文并翻译 | 示例

摘要

Security has been a growing concern for large organizations, especially financial and governmental institutions, as security breaches in the systems they depend on have repeatedly resulted in billions of dollars in losses per year, and this cost is on the rise. A primary reason for these breaches is that the systems in question are “socio-technical” a mix of people, processes, technology, and infrastructure. However, such systems are designed in a piecemeal rather than a holistic fashion, leaving parts of the system vulnerable. To tackle this problem, we propose a three-layer security analysis framework consisting of a social layer (business processes, social actors), a software layer (software applications that support the social layer), and an infrastructure layer (physical and technological infrastructure). In our proposal, global security requirements lead to local security requirements, cutting across conceptual layers, and upper-layer security analysis influences analysis at lower layers. Moreover, we propose a set of analytical methods and a systematic process that together drive security requirements analysis across the three layers. To support analysis, we have defined corresponding inference rules that (semi-)automate the analysis, helping to deal with system complexity. A prototype tool has been implemented to support analysts throughout the analysis process. Moreover, we have performed a case study on a real-world smart grid scenario to validate our approach.
机译:对于大型组织,尤其是金融和政府机构,安全性日益引起关注,因为它们所依赖的系统中的安全漏洞每年反复造成数十亿美元的损失,而且这种成本还在上升。造成这些破坏的主要原因是,所讨论的系统是“社会技术”人员,流程,技术和基础架构的组合。但是,这样的系统是零碎的而不是整体的设计,从而使系统的某些部分易受攻击。为了解决此问题,我们提出了一个三层安全分析框架,该框架由社交层(业务流程,社交参与者),软件层(支持社交层的软件应用程序)和基础结构层(物理和技术基础结构)组成。在我们的建议中,全局安全性需求导致本地安全性需求,跨越概念层,而上层安全性分析会影响较低层的分析。此外,我们提出了一套分析方法和一个系统过程,共同推动了对三层安全需求的分析。为了支持分析,我们定义了相应的推理规则,以(半)自动化分析,从而有助于处理系统复杂性。已实现了原型工具,以在整个分析过程中为分析师提供支持。此外,我们在现实世界的智能电网场景中进行了案例研究,以验证我们的方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号