کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
461028 696525 2015 15 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Automated analysis of security requirements through risk-based argumentation
ترجمه فارسی عنوان
تجزیه و تحلیل خودکار نیازهای امنیتی از طریق استدلال مبتنی بر ریسک
کلمات کلیدی
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
چکیده انگلیسی


• Included definition of premises.
• Adjusted the metamodel according to the Toulmin-style arguments.
• Revised the examples according to the changed metamodel.
• Added descriptions to Figs. 7 and 8.
• Fixed typos and improved the language.

Computer-based systems are increasingly being exposed to evolving security threats, which often reveal new vulnerabilities. A formal analysis of the evolving threats is difficult due to a number of practical considerations such as incomplete knowledge about the design, limited information about attacks, and constraints on organisational resources. In our earlier work on RISA (RIsk assessment in Security Argumentation), we showed that informal risk assessment can complement the formal analysis of security requirements. In this paper, we integrate the formal and informal assessment of security by proposing a unified meta-model and an automated tool for supporting security argumentation called OpenRISA. Using a uniform representation of risks and arguments, our automated checking of formal arguments can identify relevant risks as rebuttals to those arguments, and identify mitigations from publicly available security catalogues when possible. As a result, security engineers are able to make informed and traceable decisions about the security of their computer-based systems. The application of OpenRISA is illustrated with examples from a PIN Entry Device case study.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Journal of Systems and Software - Volume 106, August 2015, Pages 102–116
نویسندگان
, , , , ,