Mutual Refinement of Security Requirements and Architecture Using Twin Peaks Model

Mutual Refinement of Security Requirements and Architecture Using Twin Peaks Model
复制标题

DOI:
10.1109/compsacw.2012.72
复制
发表时间:
2012-07
期刊:
2012 IEEE 36th Annual Computer Software and Applications Conference Workshops
影响因子:
--
通讯作者:
T. Okubo;H. Kaiya;Nobukazu Yoshioka
T. Okubo;H. Kaiya;Nobukazu Yoshioka
中科院分区:
其他
文献类型:
--
作者:
T. Okubo;H. Kaiya;Nobukazu Yoshioka

文献摘要

相似文献

很难充分规定软件安全要求,因为它们依赖于尚未设计的软件体系结构。虽然双峰模型是一个参考模型,以引出足够数量的软件需求与架构的要求,它仍然不清楚如何安全要求可以引出,同时考虑到架构。我们提出了一种新的方法来引出的安全需求与体系结构细化的基础上的双峰模型,这是所谓的双峰模型应用程序的安全分析(TMP-SA)。在我们的方法中,安全对策的攻击引起的安全需求增量根据细化的架构。我们可以全面探索对策(安全需求)的替代方案,并为每个项目选择最合适的方案,因为我们可以专注于特定于架构的安全问题以及与架构无关的安全问题。我们已经将我们的方法应用到几个应用程序,并讨论其优点和局限性。我们发现,我们的方法是适合于迭代开发,它使我们能够找到威胁所造成的架构问题,是非常难以找到的分析时,只有需求的问题。
It is difficult to sufficiently specify software security requirements because they depend on a software architecture that has not yet been designed. Although the Twin Peaks model is a reference model to elicit a sufficient amount of software requirements in conjunction with the architectural requirements, it is still unclear how the security requirements can be elicited while taking the architecture into consideration. We propose a novel method to elicit the security requirements with architecture elaboration based on the Twin Peaks model, which is called the Twin Peaks Model application for Security Analysis (TMP-SA). In our method, security countermeasures for attacks are elicited as the security requirements incrementally according to the refinement of the architecture. We can comprehensively explore the alternatives for the countermeasures (security requirements) and choose the most suitable one for each project because we can focus on the architecture-specific security issues as well as architecture-independent security issues. We have applied our method to several applications and discuss its advantages and limitations. We found that our method is suitable for iterative development, and it enables us to find threats caused by architectural issues that are severely difficult to find when analyzing only the requirements issues.