...
首页> 外文期刊>Journal of Theoretical and Applied Information Technology >SECURITY REQUIREMENTS TEMPLATE-BASED APPROACH TO IMPROVE THE WRITING OF COMPLETE SECURITY REQUIREMENTS
【24h】

SECURITY REQUIREMENTS TEMPLATE-BASED APPROACH TO IMPROVE THE WRITING OF COMPLETE SECURITY REQUIREMENTS

机译:安全要求基于模板的方法,提高完整安全要求的写作

获取原文
           

摘要

Writing quality security requirements contributes to the success of secure software development. It has been a common practice to include security requirements in a software system after the system is defined. Thus, incorporating security requirements at a later stage of software development will increase the risks of security vulnerabilities in software development. However, the process of writing security requirements is tedious and complex. Although significant work can be found in the field of requirements elicitation, less attention has been given for writing complete security requirements. It is still a challenge and tedious process for requirements engineers (REs) to elicit and write complete security requirements that are derived from natural language. This is due to their tendency to misunderstand the real needs and the security terms used by inexperienced REs leading to incomplete security requirements. Motivated from these problems, we have developed a prototype tool, called SecureMEReq to improve the writing of complete security requirements. This tool provides four important key-features, which are (1) extraction of security requirements components from client-stakeholders; (2) validation of security requirements probability density and security requirements syntax density; (3) checking the security requirements and key-structure components; and (4) validation of completeness prioritization. To do this, we used our pattern libraries: SecLib and SRCLib to support the automation process of elicitation, especially in writing the security requirements. To evaluate our approach and tool, we have conducted completeness tests to compare the completeness of writing security requirements through the results provided by SecureMEReq and manual writing. Our evaluation results show that our prototype tool is capable to facilitate the writing of complete security requirements and useful in assisting the REs to elicit the security requirements.
机译:写作质量安全要求有助于安全软件开发的成功。在定义系统后,它是一个常见的做法,包括在软件系统中的安全要求。因此,在软件开发的稍后阶段结合安全要求将增加软件开发中的安全漏洞的风险。但是,写作安全要求的过程是乏味和复杂的。虽然在需求领域中可以找到大量工作诱因,但还可以少注意写出完整的安全要求。对于需求工程师(RES)来说,仍然是一个挑战和繁琐的过程,以引发和写出来自自然语言的完整安全要求。这是由于它们倾向误解了真实需求和未经经验的RES使用的安全术语,导致不完全安全要求。从这些问题的动机,我们开发了一个原型工具,称为Securemereq,以提高完整安全要求的写作。此工具提供了四个重要的关键功能,这些功能是(1)从客户利益相关者提取安全要求组件; (2)安全要求验证概率密度和安全要求语法密度; (3)检查安全要求和密钥结构组件; (4)完整性优先级的验证。为此,我们使用了模式库:seclib和srclib,支持elicitation的自动化过程,尤其是在编写安全要求时。为了评估我们的方法和工具,我们进行了完整性测试,以通过Securemereq和手动写入提供的结果来比较写作安全要求的完整性。我们的评估结果表明,我们的原型工具能够促进写入完全安全要求,并有助于协助RES引发安全要求。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号