谷歌浏览器插件
订阅小程序
在清言上使用

Security Requirements Engineering: A Framework for Representation and Analysis

IEEE Transactions on Software Engineering(2008)

引用 573|浏览3
暂无评分
摘要
This paper presents a framework for security requirements elicitation and analysis, based upon the construction of a context for the system, representation of security requirements as constraints, and satisfaction arguments for the requirements in the system context. The system context is described using a problem-centered notation, then is validated against the security requirements through construction of a satisfaction argument. The satisfaction argument is in two parts: a formal argument that the system can meet its security requirements, and a structured informal argument supporting the assumptions expressed in the formal argument. The construction of the satisfaction argument may fail, revealing either that the security requirement cannot be satisfied in the context, or that the context does not contain sufficient information to develop the argument. In this case, designers and architects are asked to provide additional design information to resolve the problems. We evaluate the framework by applying it to a security requirements analysis within an air traffic control technology evaluation project.
更多
查看译文
关键词
requirements engineering,argumentation,computer security,requirement engineering,it security,satisfiability,security engineering,statistics,indexing terms,software security,security,application software,data security,internet,air traffic control,information security,software engineering
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要