Modeling Security Threat Patterns to Derive Negative Scenarios

Modeling Security Threat Patterns to Derive Negative Scenarios
复制标题

对安全威胁模式进行建模以得出负面场景

DOI:
10.1109/apsec.2013.19
复制
发表时间:
2013
期刊:
Proceedings of the 20th Asia-Pacific Software Engineering Conference (APSEC 2013)
影响因子:
--
通讯作者:
Motoshi Saeki
Motoshi Saeki
中科院分区:
--
文献类型:
--
作者:
Tatsuya Abe;Shinpei Hayashi;Motoshi Saeki

文献摘要

相似文献

安全需求的引出是开发更高质量的安全业务流程和信息系统的关键问题。虽然我们有几种方法来引出安全需求,但大多数都没有提供足够的支持来识别安全威胁。由于威胁不会像异常事件那样频繁发生,因此彻底确定威胁的潜力比识别业务流程的正常行为要困难得多。为了减少这种困难,积累知识的威胁,从实际设置是必要的。在本文中,我们提出的技术来建模知识的威胁模式派生的负面情况下,实现威胁,并利用它们在业务流程建模。基于国际通用准则标准,从安全目标文档中提取知识,并在序列图上用转换规则描述模式。在我们的方法中,分析师组成的业务流程与序列图的正常情况下,和威胁模式匹配,他们派生出负面的情况。我们的方法已经证明了几个例子,以显示其实际应用。
The elicitation of security requirements is a crucial issue to develop secure business processes and information systems of higher quality. Although we have several methods to elicit security requirements, most of them do not provide sufficient supports to identify security threats. Since threats do not occur so frequently, like exceptional events, it is much more difficult to determine the potentials of threats exhaustively rather than identifying normal behavior of a business process. To reduce this difficulty, accumulated knowledge of threats obtained from practical setting is necessary. In this paper, we present the technique to model knowledge of threats as patterns by deriving the negative scenarios that realize threats and to utilize them during business process modeling. The knowledge is extracted from Security Target documents, based on the international Common Criteria Standard, and the patterns are described with transformation rules on sequence diagrams. In our approach, an analyst composes normal scenarios of a business process with sequence diagrams, and the threat patterns matched to them derives negative scenarios. Our approach has been demonstrated on several examples, to show its practical application.