首页> 外文期刊>電子情報通信学会技術研究報告. 知能ソフトウェア工学. Knowledge-Based Software Engineering >A new approach to develop a dependable security case by combining real life security experiences (lessons learnt) with D-Case development process
【24h】

A new approach to develop a dependable security case by combining real life security experiences (lessons learnt) with D-Case development process

机译:通过结合现实生活中的安全经验(经验教训)和D-Case开发过程来开发可靠的安全案例的新方法

获取原文
获取原文并翻译 | 示例
           

摘要

Our daily life reliance on software systems is growing for the purpose of convenience, efficiency, and security. Modern systems runs for long periods of time and are being constantly improved in service objectives and users' requirements under evolving technologies and changing regulations/standards. At the same time, these systems have become extremely complex. Dependability of these software systems cannot be achieved only by using conventional technologies, such as software processes and/or Formal Methods. It also needs software assurance case, which in this paper we refer to it as dependability (assurance) case or simply D-Case. Most often is the fact that D-Case (an extension form of assurance case) is most commonly associated with the safely aspect of dependability that covers the realm of dependable software application systems, embedded operating systems, information systems and so on. Because of this regard, safety cases are quite well known in comparison to other aspects of dependability like availability, integrity and confidentiality which are all co-related to security. On the other hand, D-Case has never been used in security and therefore holds the motivation behind this paper. By combining our knowledge of networking system together with our research result on the issue of security, it was found that there is guidance available, and there have been some promising experiments on the creation of security cases, although these guidance and experiments are not well documented to cover the realm of information and industrial networking systems, which this paper is about.
机译:为了方便,高效和安全,我们对软件系统的日常依赖正在增长。现代系统可以长期运行,并且随着技术的发展和法规/标准的不断变化,其服务目标和用户要求也在不断提高。同时,这些系统变得极为复杂。这些软件系统的可靠性不能仅通过使用常规技术(例如软件过程和/或形式方法)来实现。它还需要软件保证案例,在本文中我们将其称为可靠性(保证)案例或简称为D-Case。最常见的事实是,D-Case(保证案例的扩展形式)最常与可靠性的安全方面相关联,涵盖了可靠的软件应用程序系统,嵌入式操作系统,信息系统等领域。因此,与可靠性(如可用性,完整性和机密性)都与安全性相关的其他方面相比,安全案例是众所周知的。另一方面,D-Case从未在安全性中使用过,因此具有本文的动机。通过将我们对网络系统的了解与我们在安全性问题上的研究成果相结合,发现存在可用的指南,并且在创建安全性案例方面已经进行了一些有希望的实验,尽管这些指南和实验没有得到很好的记录涵盖本文所涉及的信息和工业网络系统领域。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号