Technical Meeting

コモンクライテリアをドメイン知識としたゴール指向セキュリティ要求獲得法

Goal-Oriented Security Requirements Analysis Using Common Criteria as Domain Ontology

佐伯 元司, 林 晋平, 海谷 治彦

Motoshi Saeki, Shinpei Hayashi, Haruhiko Kaiya

電子情報通信学会技術研究報告, vol. 109, no. 432, pp. 37–42, 九州工業大学 天神サテライトキャンパス, 福岡, March 2010.

Abstract

本稿では,セキュリティ機能要求を抽出するために,コモンクライテリアに準拠して書かれた文書(セキュリティターゲット)を活用する手法を述べる.セキュリティターゲットを機能要求から,脅威やセキュリティ対策を識別するための知識ソースとして用いる.我々の手法はオントロジを用いたゴール指向要求分析法(GOORE)に組み込まれている.

Abstract (English)

This paper proposes the usage of security targets, which are documents compliant to Common Criteria (ISO/IEC 15408), as related knowledge sources to identify security functional requirements from functional requirements through eliciting threats and security objectives. Our proposed technique has been combined with GOORE.

Related papers

Continued in

BibTeX

@article{saeki-sigkbse201003,
    author = {佐伯 元司 and 林 晋平 and 海谷 治彦},
    title = {コモンクライテリアをドメイン知識としたゴール指向セキュリティ要求獲得法},
    journal = {電子情報通信学会技術研究報告},
    volume = 109,
    number = 432,
    pages = {37--42},
    year = 2010,
}
Type
Technical Meeting
Location
九州工業大学 天神サテライトキャンパス, 福岡
Presented
March 5, 2010
Volume / Pages
vol. 109, no. 432, pp. 37–42