TraceSEC – Tracing and Explaining Security in Software Engineering
TraceSEC – Tracing and Explaining Security in Software Engineering
批准号:
500462081
负责人:
Professor Dr. Jan Jürjens
金额:
$0.0万
依托单位国家:
德国
项目类别:
Research Grants
财政年份:
--
资助国家:
德国
项目状态:
未结题
起止时间:
中文摘要
软件通常是不必要的不安全,因为许多软件开发人员对安全性不够熟悉。有几个问题需要持续解决:1。在开发过程中,与安全相关的工件必须集成到开发过程中。开发缺陷会导致使用中的安全问题。问题分析应该找出根源于发展的安全问题的原因。开发人员应该从开发考虑和问题分析中不断学习,以防止未来的事件并提高安全性。研究愿景:质量模型用于在几个细节层次上组织与安全相关的信息。使用工件和质量模型跟踪与安全相关的活动将同时处理所有三个核心挑战:开发、问题分析和学习。我们设想软件组织创建与安全相关的痕迹,并通过软匹配和智能操作对其进行比较和重用。自动化支持和人类判断将联合起来,使TraceSEC成为一种真正的社会技术方法。TraceSEC为与安全相关的活动引入了一种特殊的社会技术可解释性:开发组织向其成员解释为什么采取某种安全措施,如何减轻漏洞,以及如何将经验提供给个人学习的能力。科学挑战:为了达到高安全质量,我们识别相关的痕迹、工件和活动。定义识别相关元素的标准是一项主要的科学挑战。然后将相关的跟踪作为跟踪链接捕获、解释和组合,以获得语义上有意义的跟踪集合。它们可以相互比较,以找到相似的跟踪和重用用例。例如,来自以前项目的跟踪链接的集合可以指向重复出现的问题和解决方案的模式。我们设想认识到反复出现的问题和解决办法。我们重用嵌入在跟踪集合中的知识进行学习:可以收集跟踪并将其转化为来自实际案例的安全问题示例。培训材料可以根据这些轨迹生成,在上下文中显示工件和决策。确定安全的非正式、正式、启发式和可测量方面的相关内容是一项挑战。TraceSEC中最重要的机遇和挑战是将一个活动(开发、问题分析、学习)的结果重用到其他活动。这是本提案中的一个关键概念。主要贡献:我们将质量模型和跟踪结合起来,以涵盖社会技术环境中的非正式和正式活动。TraceSEC将提供结果软件的安全属性的解释性。我们计划将我们的方法集成到标准/瀑布式流程和敏捷流程中,并调查该方法对所开发软件的安全性的支持程度。
英文摘要
Software is often unnecessarily insecure since, many software developers are not sufficiently familiar with security. Several issues need to be addressed consistently:1. During development, security-related artifacts must be integrated into the development process.2. Development flaws can cause security problems in use. Problem Analysis should identify causes of security problems rooted in development.3. Developers should learn continuously from development considerations and problem analysis to prevent future incidents and improve security.Research Vision: Quality models are used to organize security-related information on several levels of detail. Tracing of security-related activities with artifacts and with the quality model will address all three core challenges at a time: development, problem analysis, and learning. We envision software organizations to create traces related to security, compare and reuse them via soft matching and intelligent operations. Automated support and human judgment will join forces and make TraceSEC a truly socio-technical approach. TraceSEC introduces a special kind of socio-technical explainability of security-related activities: the ability of a development organization to explain to its members why a certain security measure was taken, how a vulnerability was mitigated, and how the experience made is fed into individual human learning.Scientific challenges: To achieve high security quality, we identify relevant traces, artifacts, and activities. It is a main scientific challenge to define criteria for identifying relevant elements. Relevant traces will then be captured as trace links, interpreted, and combined to obtain semantically meaningful collections of traces. They can be compared with each other for finding similar traces and cases for reuse. For example, the collection of trace links from previous projects can point to recurring problems and patterns of solutions. We envision recognizing recurring problems and solutions. We reuse the knowledge engrained in collections of traces for learning: Traces can be harvested and turned into examples of security issues from real cases. Training material can be generated following those traces, showing artifacts and decisions in context. It is challenging to identify what is relevant in the informal, formal, heuristic, and measurable facets of security. The overarching opportunity and challenge in TraceSEC is to reuse results from one activity (development, problem analysis, learning) to the others. This is a key concept in this proposal.Key Contributions: We combine quality models and tracing to cover informal and formal activities in a socio-technical environment. TraceSEC will provide explainability of the security properties of the resulting software. We plan to integrate our approach into standard/waterfall and agile processes and investigate how well the methodology supports the security of the developed software.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Beyond One-Shot Security: Requirements-driven Run-time Security Adaptation to Reduce Code Patching (SecVolution@Run-time)
-
批准号:221328183
-
项目类别:Priority Programmes
-
资助金额:$0.0万
-
财政年份:2012
-
负责人:Professor Dr. Jan Jürjens
-
依托单位:
Modular Modeling of Delegation Security in Software Development (MoDelSec)
-
批准号:183482459
-
项目类别:Priority Programmes
-
资助金额:$0.0万
-
财政年份:2010
-
负责人:Professor Dr. Jan Jürjens
-
依托单位:
国内基金
海外基金
基于可配置处理器的Ray-Tracing算法专用硬件体系结构的研究
-
批准号:61070136
-
项目类别:面上项目
-
资助金额:32.0万元
-
批准年份:2010
-
负责人:孙济洲
-
依托单位: