课题基金 / 基金详情

A supporting system for predicting vulnerabilities and their countermeasures of an information system during requirements analysis

A supporting system for predicting vulnerabilities and their countermeasures of an information system during requirements analysis
需求分析过程中预测信息系统漏洞及其对策的支撑系统
批准号:
23500042
负责人:
KAIYA Haruhiko
金额:
$3.33万
依托单位:
依托单位国家:
日本
项目类别:
Grant-in-Aid for Scientific Research (C)
财政年份:
2011
资助国家:
日本
项目状态:
已结题
起止时间:
2011 至 2013

项目摘要

项目成果

KAIYA Haruhiko的其他基金

相似基金

相关文献

中文摘要
翻译
我们开发了一种安全需求分析方法。在该方法中,基于待开发系统中资产和系统架构之间的依赖关系,系统地预测漏洞及其对策。当架构改变但系统功能不变时,我们可以重新检查漏洞及其对策。我们还开发了一个辅助工具,用于制定该方法。该工具由三个组件组成:建模编辑器,模型检查器和可视化工具。在该工具的帮助下,包括安全专家在内的利益相关者可以验证该方法的预测结果,因为该工具可以在我们原有的模型检查引擎的基础上自动推导出漏洞的候选者,并可视化推导出的结果。
英文摘要
We have developed a method for security requirements analysis. In the method, vulnerabilities and their countermeasures are systematically predicted on the basis of the dependencies among assets and a system architecture in a system to be developed. We can re-examine vulnerabilities and their countermeasures when the architecture is changed but system functionalities are not changed. We have also developed a supporting tool for enacting the method. The tool consists of three components: a modeling editor, a model checker and a visualizer. With the help of the tool, stakeholders including security experts can validate the predicted results of the method because the tool can automatically derive the candidates of vulnerabilities on the basis of our original model checking engine and visualize the derived results.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1109/hase.2014.35
发表时间: 2014-01
期刊: 2014 IEEE 15th International Symposium on High-Assurance Systems Engineering
影响因子: --
作者: [T. Okubo;Nobukazu Yoshioka;H. Kaiya]
通讯作者: T. Okubo;Nobukazu Yoshioka;H. Kaiya
Effective Security Impact Analysis with Patterns for Software Enhancement
有效的安全影响分析与软件增强模式
DOI: --
发表时间: 2011
期刊:
影响因子: --
作者: [Takao Okubo, Haruhiko Kaiya, and Nobukazu Yoshioka]
通讯作者: and Nobukazu Yoshioka
Validating Quality Requirements Considerations in a Design Document using Spectrum Analysis
使用频谱分析验证设计文档中的质量要求注意事项
DOI: --
发表时间: 2012
期刊:
影响因子: --
作者: [Masahiro Umemura, Haruhiko Kaiya, Shinpei Ogata and Kenji Kaijiri]
通讯作者: Shinpei Ogata and Kenji Kaijiri
how to support software revision in software non-intensive projects using existing techniques
如何使用现有技术支持软件非密集型项目中的软件修订
DOI: --
发表时间: 2011
期刊:
影响因子: --
作者: [Haruhiko Kaiya, Kenichiro Hara, Kyotaro Kobayashi, Akira Osada, and Kenji Kaijiri.]
通讯作者: and Kenji Kaijiri.
共 15 条
    A spectrum analysis method for validating software quality requirements and for confirming their inheritance
    • 批准号:
      20500032
    • 项目类别:
      Grant-in-Aid for Scientific Research (C)
    • 资助金额:
      $2.83万
    • 财政年份:
      2008
    • 负责人:
      KAIYA Haruhiko
    • 依托单位:
    Requirements definition methane-sad on comparison among existing systems and kncwkdge ofStakeholders
    • 批准号:
      18500020
    • 项目类别:
      Grant-in-Aid for Scientific Research (C)
    • 资助金额:
      $2.59万
    • 财政年份:
      2006
    • 负责人:
      KAIYA Haruhiko
    • 依托单位:
    海外基金