首页> 外文OA文献 >Trustworthy Refinement Through Intrusion-Aware Design (TRIAD)
【2h】

Trustworthy Refinement Through Intrusion-Aware Design (TRIAD)

机译:通过入侵感知设计(TRIAD)的可靠改进

摘要

High confidence in a systemu27s survivability requires an accurate understanding of the systemu27s threat environment and the impact of that environment on system operations. Unfortunately, existing development methods for secure and survivable information systems often employ a patchwork approach in which the focus is on deciding which popular security components to integrate rather than making a rational assessment of how to address the attacks that are likely to compromise the overall mission. This report proposes an intrusion-aware design model called trustworthy refinement through intrusion-aware design (TRIAD). TRIAD helps information system decision makers formulate and maintain a coherent, justifiable, and affordable survivability strategy that addresses mission-compromising threats for their organization. TRIAD also helps in evaluating and maintaining an information system design in terms of its ability to implement a survivability strategy. This report demonstrates the application of TRIAD to the refinement of a survivability strategy for a business that sells products over the Internet.TRIAD provides a solid foundation for the further refinement, experimentation, and validation of an approach to exploit knowledge of intruder behavior to improve system architecture design and operations. Ultimately, with effective tool support and evidence of its efficacy, TRIAD will be integrated with more comprehensive life-cycle models for the development and maintenance of high-confidence systems.
机译:要对系统的生存能力充满信心,就需要准确了解系统的威胁环境以及该环境对系统操作的影响。不幸的是,现有的安全且可生存的信息系统开发方法通常采用一种拼凑的方法,该方法的重点是确定要集成哪些流行的安全组件,而不是对如何解决可能损害整个任务的攻击进行理性评估。本报告提出了一种入侵感知设计模型,称为通过入侵感知设计(TRIAD)的可信赖的改进。 TRIAD帮助信息系统决策者制定并维护一个连贯,合理且可负担的生存策略,以应对组织面临的威胁任务的威胁。 TRIAD还根据其实施生存策略的能力来帮助评估和维护信息系统设计。本报告展示了TRIAD在通过互联网销售产品的企业的生存策略的完善中的应用。TRIAD为进一步完善,试验和验证利用入侵者行为知识来改进系统的方法提供了坚实的基础。架构设计和运营。最终,借助有效的工具支持并证明其功效,TRIAD将与更全面的生命周期模型集成,以开发和维护高信任度系统。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号