节点文献

基于CC标准的等级驱动安全需求分析方法

Level Driven Security Requirement Analysis Method Based on CC Standard

【作者】 刘丰煦

【导师】 李晓红;

【作者基本信息】 天津大学 , 计算机科学与技术, 2012, 硕士

【摘要】 随着互联网的迅速发展和计算机应用普及,人们对IT产品的可信需求越来越高,其中软件安全性显得尤为重要。然而对于软件安全的研究多数集中在软件的实现过程中,致使软件需求阶段的安全问题长期处于不被重视的地位。据统计数据显示,相当比例的软件安全问题出现在软件需求阶段。而且在软件开发领域中越早解决安全问题所花费的代价也将越小。CC标准为解决软件安全需求阶段的问题提供了指导和帮助,基于CC标准分析安全需求也逐渐成为研究的共识,但是标准提出的安全需求分析方法存在着对专家知识依赖程度过高的问题。据此本文提出了安全需求等级驱动的CC标准安全功能组件选取方法,引入了安全需求等级的概念,提供了等级的划分方法和筛选安全功能组件的机制,建立起一套完整的安全需求分析的工程方法,能够为不同安全需要的系统提供不同程度的推荐组件,最终达到降低CC标准使用门槛和实现安全过程部分自动化的目标。文章还结合实际案例对等级驱动的安全需求分析方法中的每个活动都进行了详细阐述,通过与实际的安全需求分析的结果进行比照,验证了等级驱动方法的有效性。课题搭建了等级驱动的安全需求分析的基础架构,为实现基于国际标准的软件安全需求分析提供了有力的支持。同时也为将来的工作提供了研究基础。

【Abstract】 With the rapid development of the Internet and the popularization of computer applications, the software security is more and more important. However,most software security research is concentrated in the coding process of software. The safety problems in the software requirement stage are neglected for long time. Recently the statistical data has shown that a considerable proportion of the security problems are caused in software requirement phase. It is popular agreed that in the field of software development the earlier problem solved the less cost will be spent.Common Criteria can provide guidance and help to solve the problems in software security requirements phase. However, the security requirement analysis method provided by the Common Criteria is highly dependent on expert knowledge. This paper proposes a level driven security requirement analysis method based on Common Criteria standard to fulfill the different security needs for different systems. This paper introduces the security requirement levels and the mechanism of dividing levels. Then this paper describes the whole process to analysis the security requirement in details. Our analysis method can ease the analysis process and lower the threshold of using Common Criteria. To validate this method, we build a tool which implements the method. At last, compare with an actual security requirement analysis we prove the correctness of our method and analysis the existing problems.The paper introduces theory of the level driven requirements analysis method based on CC standard and its engineering system which support the international standards of the software security requirement. At the same time, but also it provide a theoretical basis for the future work.

  • 【网络出版投稿人】 天津大学
  • 【网络出版年期】2012年 07期
节点文献中: 

本文链接的文献网络图示:

本文的引文网络