Assessing security properties of software components: a software engineer's perspective

Assessing security properties of software components: a software engineer's perspective
复制标题

DOI:
10.1109/aswec.2006.13
复制
发表时间:
2006-04
期刊:
Australian Software Engineering Conference (ASWEC'06)
影响因子:
--
通讯作者:
K. Khan;Jun Han
K. Khan;Jun Han
中科院分区:
其他
文献类型:
--
作者:
K. Khan;Jun Han

文献摘要

被引文献

相似文献

提出了一种软件构件安全性的评估方案。该方案包括三个阶段:(i)系统特定的安全要求规范的封闭应用程序;(ii)组件特定的安全评级;和(iii)的候选组件的评分安全属性的评估方法。评估方案最终提供一个数字分数,指示候选组件安全属性的相对强度。该方案部分基于ISO/IEC 15408、信息技术安全评估通用标准(CC)和多元素组件比较与分析(MECCA)模型。该方案足够灵活,软件工程师可以使用,以便获得候选组件安全态势的第一手初步评估
The paper proposes an assessment scheme for the security properties of software components. The proposed scheme consists of three stages: (i) a system-specific security requirement specification of the enclosing application; (ii) a component-specific security rating; and (iii) an evaluation method for the scored security properties of the candidate component. The assessment scheme ultimately provides a numeric score indicating a relative strength of the security properties of the candidate component. The scheme is partially based on ISO/IEC 15408, the Common Criteria for Information Technology Security Evaluation (CC) and the Multi-Element Component Comparison and Analysis (MECCA) model. The scheme is flexible enough for software engineers to use in order to get a first-hand preliminary assessment of the security posture of candidate components