作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2007, Vol. 33 ›› Issue (16): 120-122. doi: 10.3969/j.issn.1000-3428.2007.16.041

• 安全技术 • 上一篇    下一篇

基于扩展i*框架的早期安全需求建模方法

王润孝1,向 冬1,王海鹏2,张 涛2   

  1. (1. 西北工业大学机电学院,西安 710072;2. 西北工业大学计算机学院,西安 710072)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2007-08-20 发布日期:2007-08-20

Early-phase Security Requirements Modeling Method Based on Extended i* Framework

WANG Run-xiao1, XIANG Dong1, WANG Hai-peng2, ZHANG Tao2   

  1. (1. College of Mechtronics, Northwestern Polytechnical University, Xi’an 710072; 2. College of Computer, Northwestern Polytechnical University, Xi’an 710072)
  • Received:1900-01-01 Revised:1900-01-01 Online:2007-08-20 Published:2007-08-20

摘要: 提出了一种基于通用准则思想的分阶段的安全需求设计方法,讨论了其中早期安全需求分析阶段的主要工作内容。在此基础上,提出一种扩展i*框架的早期安全需求建模方法,并以一个面向通用准则EAL3评估级的工业数据采集系统的需求开发活动为例,详细阐述了该方法下系统早期安全需求模型的建立过程。

关键词: 信息安全, 通用准则, 需求工程, i*框架, 工业数据采集系统

Abstract: Based on common criteria, a three-phased requirement engineering method is presented. It focuses the early-phased security requirements engineering, and proposes an extended i* framework by defining new nodes and links. The extended model can model the relationships of security environments and security objectives precisely and visually, thus help to define the required security objectives. Taking the requirement development of an industrial data acquisition system as an example, the modeling processes based on the proposed model is discussed.

Key words: information security, common criteria, requirement engineering, i* framework, industrial data acquisition system

中图分类号: