【24h】

Introducing Security Building Block Models

机译:引入安全性构建模块模型

获取原文
获取原文并翻译 | 示例

摘要

In todayâs software development process, security related design decisions are rarely made early in the overall process. Even if security is considered early, this means that in most cases a more-or-less encompassing security requirement analyses is made, Based on this analysis best-practices, ad-hocdesign decisions or individual expertise is used to integrate security during the development process or after weaknesses are found after the deployment. This paper introduces Security Building Block Models which are used to build security related components, namely Security Building Blocks. These Security Building Blocks represent concrete security solutions, so called Security Properties, introduced in other publications of the Sec Futur project. The goal of this approach is to provide already defined and tested security related software components, which can be used early in the overall development process, to support security-design-decision already while modeling the software-system. The paper shortly describes this new Security Engineering Process with its requirement analysis and definition of Security Properties and how the Security Building Block Model fits into this approach. Additionally the Security Building Block Model is presented in detail. All artifacts and relationships of the model are described. Short examples finish up the paper to show the creation of the Security Building Blocks and their interactions with other software components.
机译:在当今的软件开发过程中,很少在整个过程的早期做出与安全相关的设计决策。即使较早考虑安全性,这也意味着在大多数情况下,都会进行或多或少的安全性需求分析,基于这种最佳实践,在开发过程中会使用临时设计决策或个人专业知识来集成安全性或在部署后发现弱点之后。本文介绍了用于构建与安全相关的组件(即安全构件)的安全构件模块模型。这些安全构建块代表了Sec Futur项目的其他出版物中介绍的具体安全解决方案,即所谓的安全属性。这种方法的目标是提供已经定义和测试的与安全性相关的软件组件,可以在整个开发过程的早期使用这些组件,以在对软件系统进行建模时已经支持安全性设计决策。本文简要介绍了这一新的安全工程流程,包括其需求分析和安全属性的定义,以及安全构建模块模型如何适合这种方法。此外,还将详细介绍安全性构建模块模型。描述了模型的所有工件和关系。简短的示例完成了本文,以显示安全构建块的创建以及它们与其他软件组件的交互。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号