【24h】

Towards a Comprehensive Framework for Secure Systems Development

机译:建立安全系统开发的全面框架

获取原文
获取原文并翻译 | 示例

摘要

Security involves technical as well as social challenges. In the development of security-critical applications, system developers must consider both the technical and the social parts. To achieve this, security issues must be considered during the whole development life-cycle of an information system. This paper presents an approach that allows developers to consider both the social and the technical dimensions of security through a structured and well defined process. In particular, the proposed approach takes the high-level concepts and modelling activities of the secure Tropos methodology and enriches them with a low level security-engineering ontology and models derived from the UMLsec approach. A real case study from the e-commerce sector is employed to demonstrate the applicability of the approach.
机译:安全涉及技术和社会挑战。在开发安全性至关重要的应用程序时,系统开发人员必须同时考虑技术和社交方面。为此,必须在信息系统的整个开发生命周期中考虑安全问题。本文提出了一种方法,使开发人员可以通过结构化且定义明确的过程来考虑安全性的社会和技术方面。特别地,所提出的方法采用了安全Tropos方法的高级概念和建模活动,并通过低级安全工程本体和从UMLsec方法派生的模型来丰富它们。来自电子商务部门的真实案例研究被用来证明该方法的适用性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号