A framework for usable and secure system design

A framework for usable and secure system design
复制标题

可用且安全的系统设计框架

DOI:
--
复制
发表时间:
2011
期刊:
影响因子:
--
通讯作者:
Shamal Faily
Shamal Faily
中科院分区:
--
文献类型:
--
作者:
Shamal Faily

文献摘要

被引文献

相似文献

尽管在设计的早期阶段就在处理安全性和可用性问题方面的现有工作,但在将这些领域的贡献综合为指定和设计系统的过程中几乎没有工作。如果没有更好地了解如何在早期处理这两个问题的情况下,设计过程可能会剥夺利益相关者的权利,而最终的系统可能不会位于其使用情况下。该论文解决的研究问题是如何整合和改进技术和工具以支持可用和安全系统的设计。为了建立这种理解,我们提出虹膜(整合需求和信息安全性)---指定可用和安全系统的框架。 Iris从三个不同的角度考虑了系统设计过程---可用性,安全性和需求 - - 指导选择综合安全性,可用性和需求工程过程的技术。本文声称,艾里斯(Iris)是将现有技术和工具集成到可用和安全系统的设计的典范。特别是,艾里斯(Iris)为既定的研究问题做出了三项重大贡献。首先,提出了针对可用安全需求工程的概念模型,并在其上建立了虹膜框架;该元模型为更改的启发和规范技术提供了信息,以改善设计过程中的互操作性。其次,引入和指定可用和安全的系统所需的工具支持的几种特征;提出了凯里(Cairis)(需求和信息安全性的计算机协助集成)软件工具,以说明如何体现这些特征。第三,我们描述了如何使用IRIS的结果来改善以用户为中心的设计技术的设计用于安全系统设计。我们通过将虹膜框架应用于三个案例研究来验证论文。首先,IRIS用于指定英国水公司使用的软件存储库的要求。在第二个中,IRIS用于指定支持医学研究数据共享的元数据存储库的安全要求。在最终的案例研究中,IRIS用于分析英国水公司的拟议安全政策,并确定缺失的政策要求。在每个案例研究中,虹膜都在行动研究干预措施的背景下应用,其中一个案例研究的发现和经验教训被纳入了下一个案例计划。
Despite existing work on dealing with security and usability concerns during the early stages of design, there has been little work on synthesising the contributions of these fields into processes for specifying and designing systems. Without a better understanding of how to deal with both concerns at an early stage, the design process risks disenfranchising stakeholders, and resulting systems may not be situated in their contexts of use. The research problem this thesis addresses is how techniques and tools can be integrated and improved to support the design of usable and secure systems. To develop this understanding, we present IRIS (Integrating Requirements and Information Security) --- a framework for specifying usable and secure systems. IRIS considers the system design process from three different perspectives --- Usability, Security, and Requirements --- and guides the selection of techniques towards integrative Security, Usability, and Requirements Engineering processes. This thesis claims that IRIS is an exemplar for integrating existing techniques and tools towards the design of usable and secure systems. In particular, IRIS makes three significant contributions towards the stated research problem. First, a conceptual model for usable secure Requirements Engineering is presented, upon which the IRIS framework is founded; this meta-model informs changes to elicitation and specification techniques for improved interoperability in the design process. Second, several characteristics of tool-support needed to elicit and specify usable and secure systems are introduced; the CAIRIS (Computer Aided Integration of Requirements and Information Security) software tool is presented to illustrate how these characteristics can be embodied. Third, we describe how the results of applying IRIS can be used to improve the design of existing User-Centered Design techniques for secure systems design. We validate the thesis by applying the IRIS framework to three case studies. In the first, IRIS is used to specify requirements for a software repository used by a UK water company. In the second, IRIS is used to specify security requirements for a meta-data repository supporting the sharing of medical research data. In the final case study, IRIS is used to analyse a proposed security policy at a UK water company, and identify missing policy requirements. In each case study, IRIS is applied within the context of an Action Research intervention, where findings and lessons from one case study are fed into the action plan of the next.