Technical Meeting

コモンクライテリアをドメイン知識としたゴール指向セキュリティ要求獲得法

Goal-Oriented Security Requirements Analysis Using Common Criteria as Domain Ontology

佐伯 元司, 林 晋平, 海谷 治彦

Motoshi Saeki, Shinpei Hayashi, Haruhiko Kaiya

電子情報通信学会技術研究報告, vol. 109, no. 432, pp. 37–42, 九州工業大学 天神サテライトキャンパス, 福岡, March 2010.

Abstract

本稿では,セキュリティ機能要求を抽出するために,コモンクライテリアに準拠して書かれた文書(セキュリティターゲット)を活用する手法を述べる.セキュリティターゲットを機能要求から,脅威やセキュリティ対策を識別するための知識ソースとして用いる.我々の手法はオントロジを用いたゴール指向要求分析法(GOORE)に組み込まれている.

Abstract (English)

This paper proposes the usage of security targets, which are documents compliant to Common Criteria (ISO/IEC 15408), as related knowledge sources to identify security functional requirements from functional requirements through eliciting threats and security objectives. Our proposed technique has been combined with GOORE.

BibTeX

@article{saeki-sigkbse201003,
    author = {佐伯 元司 and 林 晋平 and 海谷 治彦},
    title = {コモンクライテリアをドメイン知識としたゴール指向セキュリティ要求獲得法},
    journal = {電子情報通信学会技術研究報告},
    volume = 109,
    number = 432,
    pages = {37--42},
    year = 2010,
}
Type
Technical Meeting
Location
九州工業大学 天神サテライトキャンパス, 福岡
Presented
March 5, 2010
Volume / Pages
vol. 109, no. 432, pp. 37–42