首页> 美国卫生研究院文献>other >Automating Risk Analysis of Software Design Models
【2h】

Automating Risk Analysis of Software Design Models

机译:软件设计模型的自动化风险分析

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

The growth of the internet and networked systems has exposed software to an increased amount of security threats. One of the responses from software developers to these threats is the introduction of security activities in the software development lifecycle. This paper describes an approach to reduce the need for costly human expertise to perform risk analysis in software, which is common in secure development methodologies, by automating threat modeling. Reducing the dependency on security experts aims at reducing the cost of secure development by allowing non-security-aware developers to apply secure development with little to no additional cost, making secure development more accessible. To automate threat modeling two data structures are introduced, identification trees and mitigation trees, to identify threats in software designs and advise mitigation techniques, while taking into account specification requirements and cost concerns. These are the components of our model for automated threat modeling, AutSEC. We validated AutSEC by implementing it in a tool based on data flow diagrams, from the Microsoft security development methodology, and applying it to VOMS, a grid middleware component, to evaluate our model's performance.
机译:互联网和联网系统的发展使软件面临越来越多的安全威胁。软件开发人员对这些威胁的响应之一是在软件开发生命周期中引入了安全活动。本文介绍了一种方法,该方法可通过自动进行威胁建模来减少在软件中执行风险分析所需的昂贵人力资源,而这在安全开发方法中很常见。减少对安全专家的依赖旨在通过允许不具备安全意识的开发人员以很少甚至没有额外的成本来应用安全开发,从而降低安全开发的成本,从而使安全开发更容易访问。为了自动进行威胁建模,引入了两个数据结构,即识别树和缓解树,以识别软件设计中的威胁并建议缓解技术,同时考虑到规格要求和成本问题。这些是我们用于自动威胁建模的模型AutSEC的组成部分。我们通过基于Microsoft安全开发方法的基于数据流程图的工具中实现AutSEC并将其应用于网格中间件组件VOMS来评估模型的性能,从而对AutSEC进行了验证。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号