首页> 外文会议>International conference on information security and cryptology >A Model-Driven Security Requirements Approach to Deduce Security Policies Based on OrBAC
【24h】

A Model-Driven Security Requirements Approach to Deduce Security Policies Based on OrBAC

机译:基于模型的安全需求推导基于OrBAC的安全策略

获取原文

摘要

Attacks on unsecured systems result in important loses. Many of the causes are related to non-conformance of system architecture and implementation to the requirements. To reduce these conformity problems, Model Driven Engineering proposes using modelling languages for defining requirements and architecture and model transformations between them. We therefore introduce a modelling language extension/ profile for defining system requirements with basic security requirement concepts. We also formalize the model transformation between this profile and a security formal verification method. We exemplify our approach on a medical case study.
机译:对不安全系统的攻击会导致重大损失。许多原因与系统架构和实现要求的不符合有关。为了减少这些一致性问题,模型驱动工程提议使用建模语言来定义需求和体系结构以及它们之间的模型转换。因此,我们引入了一种建模语言扩展/配置文件,用于使用基本的安全需求概念来定义系统需求。我们还将形式化此配置文件和安全形式验证方法之间的模型转换形式化。我们将在医学案例研究中举例说明我们的方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号