首页> 外文期刊>International Journal of Information Security >Effectiveness and performance analysis of model-oriented security requirements engineering to elicit security requirements: a systematic solution for developing secure software systems
【24h】

Effectiveness and performance analysis of model-oriented security requirements engineering to elicit security requirements: a systematic solution for developing secure software systems

机译:面向模型的安全需求工程的有效性和性能分析,以得出安全需求:开发安全软件系统的系统解决方案

获取原文
获取原文并翻译 | 示例
       

摘要

Software systems are becoming more and more critical in every domain of human society. These systems are used not only by corporates and governments, but also by individuals and across networks of organizations. The wide use of software systems has resulted in the need to contain a large amount of critical information and processes, which certainly need to remain secure. As a consequence, it is important to ensure that the systems are secure by considering security requirements at the early phases of software development life cycle. In this paper, we propose to consider security requirements as functional requirements and apply model-oriented security requirements engineering framework as a systematic solution to elicit security requirements for e-governance software systems. As the result, high level of security can be achieved by more coverage of assets and threats, and identifying more traces of vulnerabilities in the early stages of requirements engineering. This in turn will help to elicit effective security requirements as countermeasures with business requirements.
机译:在人类社会的各个领域,软件系统都变得越来越重要。这些系统不仅由公司和政府使用,而且还由个人和跨组织网络使用。软件系统的广泛使用导致需要包含大量关键信息和过程,而这些信息和过程当然必须保持安全。因此,重要的是在软件开发生命周期的早期阶段通过考虑安全性要求来确保系统的安全性。在本文中,我们建议将安全需求视为功能需求,并应用面向模型的安全需求工程框架作为系统解决方案,以得出电子政务软件系统的安全需求。结果,可以通过对资产和威胁的更多覆盖以及在需求工程的早期阶段识别出更多的漏洞痕迹来实现高级别的安全性。反过来,这将有助于引发有效的安全性要求,以此作为对业务要求的对策。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号