课题基金 / 基金详情

Beyond One-Shot Security: Requirements-driven Run-time Security Adaptation to Reduce Code Patching (SecVolution@Run-time)

Beyond One-Shot Security: Requirements-driven Run-time Security Adaptation to Reduce Code Patching (SecVolution@Run-time)
超越一次性安全:需求驱动的运行时安全适应,以减少代码修补 (SecVolution@Run-time)
批准号:
221328183
负责人:
Professor Dr. Jan Jürjens
金额:
$0.0万
依托单位国家:
德国
项目类别:
Priority Programmes
财政年份:
2012
资助国家:
德国
项目状态:
已结题
起止时间:
2011-12-31 至 2020-12-31

项目摘要

项目成果

Professor Dr. Jan Jürjens的其他基金

相似基金

相关文献

中文摘要
翻译
信息系统面临着不断变化的环境,需要不断更新。软件的“老化”不是因为磨损,而是因为不能跟上环境的变化。安全性是现代信息系统中越来越重要的质量方面。同时,受上述“软件老化”风险的影响尤为严重。当信息系统处理公司或组织的资产时,任何安全漏洞都可以被攻击者利用。攻击者的知识和技术的进步是上述安全相关信息系统环境的一部分。因此,过时的安全预防措施可能会造成突然和重大的损失。因此,长寿信息系统的安全需要知识和软件的持续和系统的发展来保护。我们的目标是开发支持安全需求的技术、工具和流程,并为不断发展的信息系统设计分析技术,以确保“终身”符合安全需求。我们将建立在安全需求和设计方法SecReq在以前的联合工作中开发。作为一个核心功能,这种方法支持重用在安全关键软件开发过程中获得的安全工程经验,并将其反馈到开发过程中。我们将开发启发式的工具和技术,支持在环境中的相关变化的启发。调查结果将正式化,用于半自动安全更新。在长期信息系统的发展过程中,环境的变化将受到监测,并转化为保持或恢复其安全水平的适应性。
英文摘要
Information systems are exposed to constantly changing environments which require constant updating. Software "ages" not by wearing out, but by failing to keep up-to-date with its environment. Security is an increasingly important quality aspect in modern information systems. At the same time, it is particularly affected by the above-mentioned risk of "software ageing". When an information system handles assets of a company or an organization, any security loophole can be exploited by attackers. Advances in knowledge and technology of attackers are part of the above-mentioned environment of a security-relevant information system. Outdated security precautions can, therefore, permit sudden and substantial losses. Security in long-living information systems, thus, requires an on-going and systematic evolution of knowledge and software for its protection. Our objective is to develop techniques, tools, and processes that support security requirements and design analysis techniques for evolving information systems in order to ensure "lifelong" compliance to security requirements. We will build on the security requirements & design approach SecReq developed in previous joint work. As a core feature, this approach supports reusing security engineering experience gained during the development of security-critical software and feeding it back into the development process. We will develop heuristic tools and techniques that support elicitation of relevant changes in the environment. Findings will be formalized for semi-automatic security updates. During the evolution of a long-living information system, changes in the environment will be monitored and translated to adaptations that preserve or restore its security level.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Modular Modeling of Delegation Security in Software Development (MoDelSec)
  • 批准号:
    183482459
  • 项目类别:
    Priority Programmes
  • 资助金额:
    $0.0万
  • 财政年份:
    2010
  • 负责人:
    Professor Dr. Jan Jürjens
  • 依托单位:
TraceSEC – Tracing and Explaining Security in Software Engineering
  • 批准号:
    500462081
  • 项目类别:
    Research Grants
  • 资助金额:
    $0.0万
  • 财政年份:
    --
  • 负责人:
    Professor Dr. Jan Jürjens
  • 依托单位:
国内基金
海外基金
适配硬件和任务的One-shot神经网络架构搜索
  • 批准号:
    62006226
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    24.0万元
  • 批准年份:
    2020
  • 负责人:
    陈亚冉
  • 依托单位: