Introducing Vulnerability Awareness to Common Criteria's Security Targets

Porto(2009)

引用 14|浏览2
暂无评分
摘要
Security of software systems has become one of the biggest concerns in our everyday life, since software systems are increasingly used by individuals, companies and governments. One way to help software system consumers gain assurance about the security measures of software products is to evaluate and certify these products with standard evaluation processes. The Common Criteria (ISO/IEC 15408) evaluation scheme is a standard that is widely used by software vendors. This process does not include information about already known vulnerabilities, their attack data and lessons learned from them. This has resulted in criticisms concerning the accuracy of this evaluation scheme since it might not address the areas in which actual vulnerabilities might occur. In this paper, we present a methodology that introduces information about threats from vulnerabilities to Common Criteria documents. Our methodology improves the accuracy of the Common Criteria by providing information about known vulnerabilities in Common Criteria’s security target. Our methodology also provides documentation about how to fulfill certain security requirements, which can reduce the time for evaluation of the products.
更多
查看译文
关键词
introducing vulnerability awareness,software system,certain security requirement,software system consumers gain,security measure,software product,common criteria,software vendor,common criteria document,evaluation scheme,security targets,security target,security,programming,documentation,data mining,distributed databases,natural sciences,object recognition,software systems,computer science,technology,accuracy
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要