【24h】

Information Modeling for Automated Risk Analysis

机译:自动化风险分析的信息建模

获取原文
获取原文并翻译 | 示例

摘要

Systematic security risk analysis requires an information model which integrates the system design, the security environment (the attackers, security goals etc) and proposed security requirements. Such a model must be scalable to accommodate large systems, and support the efficient discovery of threat paths and the production of risk-based metrics; the modeling approach must balance complexity, scalability and expressiveness. This paper describes such a model; novel features include combining formal information modeling with informal requirements traceability to support the specification of security requirements on incompletely specified services, and the typing of information flow to quantify path exploitability and model communications security.
机译:系统的安全风险分析需要一个信息模型,该信息模型集成了系统设计,安全环境(攻击者,安全目标等)和建议的安全要求。这种模型必须可扩展,以适应大型系统,并支持有效发现威胁路径和生成基于风险的度量标准;建模方法必须在复杂性,可伸缩性和表达能力之间取得平衡。本文描述了这样一个模型。新颖的功能包括将形式化的信息建模与非正式的需求可追溯性相结合,以支持对不完整指定服务的安全性要求的规范;以及信息流的类型化,以量化路径可利用性并为通信安全性建模。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号