首页> 外文OA文献 >An Approach to Security Requirements Engineering for a High Assurance System
【2h】

An Approach to Security Requirements Engineering for a High Assurance System

机译:一种高保障系统的安全需求工程方法

摘要

Requirements specifications for high assurance secure systems are rare in the open literature. This paper examines the development of a requirements document for a multilevel secure system that must meet stringent assurance and evaluation requirements. The system is designed to be secure, yet combines popular commercial components with specialized high assurance ones. Functional and non-functional requirements pertinent to security are discussed. A multi-dimensional threat model is presented. The threat model accounts for the developmental and operational phases of system evolution and for each phase accounts for both physical and non-physical threats. We describe our team-based method for developing a requirements document and relate that process to techniques in requirements engineering. The system requirements document presented provides a calibration point for future security requirements engineering techniques intended to meet both functional and assurance goals.
机译:高安全性系统的需求规范在公开文献中很少见。本文研究了必须满足严格的保证和评估要求的多层安全系统的要求文档的开发。该系统设计为安全的,但将流行的商业组件与专门的高保证组件结合在一起。讨论了与安全性相关的功能和非功能需求。提出了多维威胁模型。威胁模型说明了系统演化的发展和运营阶段,每个阶段都说明了物理威胁和非物理威胁。我们描述了用于开发需求文档的基于团队的方法,并将该过程与需求工程中的技术相关联。提出的系统需求文档为将来旨在满足功能和保证目标的安全需求工程技术提供了一个校准点。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号