首页> 外文会议>Advanced information systems engineering workshops >Security Requirements Analysis Using Knowledge in CAPEC
【24h】

Security Requirements Analysis Using Knowledge in CAPEC

机译:使用CAPEC中的知识进行安全需求分析

获取原文
获取原文并翻译 | 示例

摘要

Because all the requirements analysts are not the experts of security, providing security knowledge automatically is one of the effective means for supporting security requirements elicitation. We propose a method for eliciting security requirements on the basis of Common Attack Patterns Enumeration and Classification (CAPEC). A requirements analyst can automatically acquire the candidates of attacks against a functional requirement with the help of our method. Because technical terms are mainly used in the descriptions in CAPEC and usual phrases are used in the requirements descriptions, there are gaps between them. To bridge the gaps, our method contains a mapping between technical terms and noun phrases called term maps.
机译:由于所有需求分析人员都不是安全专家,因此自动提供安全知识是支持安全需求确定的有效手段之一。我们提出了一种基于通用攻击模式枚举和分类(CAPEC)得出安全要求的方法。需求分析人员可以借助我们的方法自动获取针对功能需求的攻击候选对象。由于在CAPEC的描述中主要使用技术术语,而在需求描述中则使用常用的短语,因此它们之间存在差距。为了弥合差距,我们的方法包含技术术语与名词术语之间的映射,称为术语图。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号