...
首页> 外文期刊>ACM Transaction on Information and System Security >Iterative Analysis to Improve Key Properties of Critical Human-Intensive Processes: An Election Security Example
【24h】

Iterative Analysis to Improve Key Properties of Critical Human-Intensive Processes: An Election Security Example

机译:迭代分析以改善关键的人类密集过程的关键属性:选举安全示例

获取原文
获取原文并翻译 | 示例
           

摘要

In this article, we present an approach for systematically improving complex processes, especially those involving human agents, hardware devices, and software systems. We illustrate the utility of this approach by applying it to part of an election process and show how it can improve the security and correctness of that subprocess. We use the Little-JIL process definition language to create a precise and detailed definition of the process. Given this process definition, we use two forms of automated analysis to explore whether specified key properties, such as security and safety policies, can be undermined. First, we use model checking to identify process execution sequences that fail to conform to event-sequence properties. After these are addressed, we apply fault tree analysis to identify when the misperformance of steps might allow undesirable outcomes, such as security breaches. The results of these analyses can provide assurance about the process; suggest areas for improvement; and, when applied to a modified process definition, evaluate proposed changes.
机译:在本文中,我们提出了一种系统地改善复杂过程的方法,尤其是涉及人员代理,硬件设备和软件系统的过程。我们通过将这种方法应用于选举过程的一部分来说明该方法的效用,并说明它如何提高该子过程的安全性和正确性。我们使用Little-JIL流程定义语言来创建流程的精确而详细的定义。根据此流程定义,我们使用两种形式的自动化分析来探究是否可以破坏指定的关键属性(例如安全性和安全性策略)。首先,我们使用模型检查来识别不符合事件序列属性的流程执行序列。在解决了这些问题之后,我们将应用故障树分析来确定步骤的错误执行何时可能导致不良后果,例如安全漏洞。这些分析的结果可以为过程提供保证;提出需要改进的地方;并将其应用于修改后的流程定义时,评估建议的更改。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号