...
首页> 外文期刊>International journal of information and computer security >Towards ontological approach to eliciting risk-based security requirements
【24h】

Towards ontological approach to eliciting risk-based security requirements

机译:迈向基于风险的安全需求的本体论方法

获取原文
获取原文并翻译 | 示例
           

摘要

Security requirements managers aim at eliciting, reusing and keeping their sets of requirements. They desire well defined, consistent and up to date requirements throughout the system lifecycle. This paper presents security ontology (SO) which can be used as a basis for eliciting risk-based security requirements. The ontology is based on the security relationship model described in the national institute of standards and technology special publication 800-12 but use-misuse case concepts and some extensions were used. We extended use case with some elements (action and object) to facilitate information system (IS) security policy instantiation after the system has been deployed. We incorporated risk and privilege concepts in order to represent risk knowledge in an unambiguous way and to enable ontology control security issues respectively. This ontology enriches the modelling and management of risk-based safeguard requirements within the requirements engineering discipline by organising the security knowledge to form heavy weight ontology which include concepts, concept taxonomies, relationships, properties, axioms and constraints. This ontology provides capabilities such as IS security management, traceability and reuse. OWL protege 3.3.1 editor was used for the ontology coding. The results of its adoption in capturing safeguard requirements of healthcare IS were also discussed.
机译:安全需求管理器旨在引发,重用和保留其需求集。他们希望在整个系统生命周期中定义明确,一致且最新。本文介绍了安全本体(SO),可以将其用作引发基于风险的安全要求的基础。本体基于国家标准和技术研究所特殊出版物800-12中描述的安全关系模型,但是使用了滥用案例概念和一些扩展。我们在用例中扩展了一些元素(动作和对象),以方便在系统部署后实例化信息系统(IS)安全策略。我们合并了风险和特权概念,以便以明确的方式表示风险知识并分别启用本体控制安全性问题。该本体通过组织安全知识以形成包括概念,概念分类法,关系,属性,公理和约束的重量级本体,丰富了需求工程学科中基于风险的保障需求的建模和管理。该本体提供诸如IS安全管理,可追溯性和重用之类的功能。 OWL protege 3.3.1编辑器用于本体编码。还讨论了其在捕获医疗保健保障要求方面的采用结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号