首页> 外国专利> Security threat identification/testing using annotated sequence diagrams

Security threat identification/testing using annotated sequence diagrams

机译:使用带注释的序列图进行安全威胁识别/测试

摘要

Embodiments provide apparatuses and methods supporting software development teams in identifying potential security threats, and then testing those threats against under-development scenarios. At design-time, embodiments identify potential threats by providing sequence diagrams enriched with security annotations. Security information captured by the annotations can relate to topics such as security goals, properties of communications channels, environmental parameters, and/or WHAT-IF conditions. The annotated sequence diagram can reference an extensible catalog of functions useful for defining message content. Once generated, the annotated sequence diagram can in turn serve as a basis for translation into a formal model of system security. At run-time, embodiments support development teams in testing, by exploiting identified threats to automatically generate and execute test-cases against the up and running scenario. The security annotations may facilitate detection of subtle flaws in security logic, e.g., those giving rise to Man-in-the-middle, authentication, and/or confidentiality issues in software under-development.
机译:实施例提供了支持软件开发团队识别潜在安全威胁,然后针对开发不足场景测试那些威胁的装置和方法。在设计时,实施例通过提供富含安全注释的序列图来识别潜在威胁。批注捕获的安全信息可以与主题相关,例如安全目标,通信通道的属性,环境参数和/或WHAT-IF条件。带注释的序列图可以引用可用于定义消息内容的功能的可扩展目录。一旦生成,带注释的序列图又可以用作转换为系统安全性正式模型的基础。在运行时,实施例通过利用已识别的威胁来针对启动和运行场景自动生成并执行测试用例,从而支持开发团队进行测试。安全注释可以促进安全逻辑中的细微缺陷的检测,例如那些在软件开发中引起中间人,身份验证和/或机密性问题的缺陷。

著录项

  • 公开/公告号US9565201B2

    专利类型

  • 公开/公告日2017-02-07

    原文格式PDF

  • 申请/专利权人 LUCA COMPAGNA;SERENA PONTA;

    申请/专利号US201514667363

  • 发明设计人 LUCA COMPAGNA;SERENA PONTA;

    申请日2015-03-24

  • 分类号H04L29/06;G06F21/57;

  • 国家 US

  • 入库时间 2022-08-21 13:41:14

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号