...
首页> 外文期刊>Journal of computer security >A catalogue associating security patterns and attack steps to design secure applications
【24h】

A catalogue associating security patterns and attack steps to design secure applications

机译:与安全模式和攻击步骤相关联以设计安全应用程序的目录

获取原文
获取原文并翻译 | 示例
           

摘要

Design Patterns are now widely accepted and used in software engineering; they represent generic and reusable solutions to common problems in software design. Security patterns are specialised patterns whose purpose is to help design applications that should meet security requirements. The enthusiasm surrounding security patterns has made emerge several catalogues listing up to 180 different patterns at the moment. This growing number brings an increased difficulty in choosing the most appropriate patterns for a given design problem. We propose a security pattern classification to facilitate the security pattern choice and a classification method based on data integration. The classification exposes relationships among software attacks, security principles and security patterns. It expresses the pattern combinations that are countermeasures to a given attack. This classification is semi-automatically inferred by means of a data-store integrating disparate publicly available security data. The data-store is also used to generate Attack Defense Trees . In our context, these illustrate, for a given attack, its sub-attacks, steps, techniques and the related defenses given under the form of security pattern combinations. Such trees make the pattern classification more readable even for beginners in security patterns. Finally, we evaluate on human subjects the benefits of using a pattern classification established for Web applications, which covers 215 attacks, 66 security principles and 26 security patterns.
机译:设计模式现在被软件工程广泛接受并使用。它们代表了针对软件设计中常见问题的通用且可重用的解决方案。安全模式是专用模式,其目的是帮助设计应满足安全要求的应用程序。围绕安全模式的热情使现在已经出现了多个目录,列出了多达180种不同的模式。对于给定的设计问题,越来越多的数量给选择最合适的模式带来了更大的困难。我们提出一种安全模式分类,以方便安全模式的选择,并提出一种基于数据集成的分类方法。分类揭示了软件攻击,安全性原则和安全性模式之间的关系。它表示作为对特定攻击的对策的模式组合。此分类是通过集成完全不同的公共安全数据的数据存储库半自动得出的。数据存储区还用于生成攻击防御树。在我们的上下文中,这些说明了对于给定的攻击,其子攻击,步骤,技术以及以安全模式组合形式给出的相关防御。这样的树使模式分类甚至对于安全模式的初学者来说也更具可读性。最后,我们针对人类受试者评估使用针对Web应用程序建立的模式分类的好处,该模式分类涵盖215种攻击,66种安全原则和26种安全模式。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号