首页> 外文OA文献 >Security Risk Assessment of Software Architecture
【2h】

Security Risk Assessment of Software Architecture

机译:软件体系结构安全风险评估

摘要

Security risk assessment is considered a significant and indispensable process in all phases of software development life cycles, and most importantly at the early phases. Estimating the security risk should be integrated with the other product developments parts and this will help developers and engineers determine the risky elements in the software system, and reduce the failure consequences in that software. This is done by building models based on the data collected at the early development cycles. These models will help identify the high security risk elements. In this paper, we introduce a new methodology used at the early phases based on the Unified Modeling Language (UML), Attack graph, and other factors. We estimate the probability and severity of security failure for each element in software architecture based on UML, attack graph, data sensitivity analysis, access rights, and reachability matrix. Then risk factors are computed. An e-commerce case study is investigated as an example. Index Terms — Attack Graph, Probability of security failure, Security risk factor, Severity of security failure, Software Architecture.
机译:安全风险评估被认为是软件开发生命周期所有阶段中的重要且必不可少的过程,最重要的是在早期阶段。估计安全风险应与其他产品开发部分集成在一起,这将有助于开发人员和工程师确定软件系统中的风险要素,并减少该软件中的故障后果。这是通过根据早期开发周期中收集的数据构建模型来完成的。这些模型将有助于识别高安全风险元素。在本文中,我们介绍了一种基于统一建模语言(UML),攻击图和其他因素的早期方法。我们基于UML,攻击图,数据敏感性分析,访问权限和可及性矩阵,估计软件体系结构中每个元素的安全失败的可能性和严重性。然后计算风险因素。以电子商务案例研究为例。索引词-攻击图,安全失败的可能性,安全风险因素,安全失败的严重程度,软件体系结构。

著录项

  • 作者

    Hassouneh Yousef; Ammar Hany;

  • 作者单位
  • 年度 2011
  • 总页数
  • 原文格式 PDF
  • 正文语种 en_US
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号