计算机应用 ›› 2013, Vol. 33 ›› Issue (07): 2041-2045.DOI: 10.11772/j.issn.1001-9081.2013.07.2041

• 计算机软件技术 • 上一篇    下一篇

安全苛求软件需求规格中的安全特性验证方法

王飞,郭渊博,李波,郝耀辉   

  1. 信息工程大学 网络空间安全学院,郑州450004
  • 收稿日期:2013-01-22 修回日期:2013-03-04 出版日期:2013-07-01 发布日期:2013-07-06
  • 通讯作者: 王飞
  • 作者简介:王飞(1985-),男,内蒙古乌兰察布人,硕士研究生,主要研究方向:信息管理系统;郭渊博(1975-),男,陕西周至人,副教授,博士,主要研究方向:网络与通信、信息与网络安全;李波(1985-),男,湖北枣阳人,硕士研究生,主要研究方向:网络应用;郝耀辉(1978-),女,河南兰考人,讲师,主要研究方向:信息与网络安全。
  • 基金资助:

    河南省科技创新杰出青年计划项目(104100510025)

Validation method of security features in safety critical software requirements specification

WANG Fei,GUO Yuanbo,LI Bo,HAO Yaohui   

  1. College of Cyberspace Security, Information Engineering University, Zhengzhou Henan 450004, China
  • Received:2013-01-22 Revised:2013-03-04 Online:2013-07-06 Published:2013-07-01
  • Contact: WANG Fei

摘要: 针对自然语言描述的安全苛求软件需求规格中安全特性不准确、不一致等问题,提出一种基于UMLsec安全特性验证方法。该方法在UML需求模型类图和顺序图的基础上,为核心类的安全特性自定义构造型、标记和约束,完成UMLsec模型构建;之后,使用设计实现的UMLsec支持工具对安全特性进行自动验证。实验结果表明,该方法能准确描述安全苛求软件需求规格的安全特性,同时可以自动验证安全特性是否满足安全需求。

关键词: UMLsec, 安全特性, 验证

Abstract: Since the security features described by natural language in the safety-critical software requirements specification are of inaccuracy and inconsistence, a validation method of security features based on UMLsec was proposed. The method completed the UMLsec model by customizing stereotypes, tags and constraints for security features of the core class on the basis of class diagram and sequence diagram for UML requirements model. Afterwards, the support tool for designing and implementing UMLsec was used for automatic verification of security features. The experimental results show that the proposed method can accurately describe security features in the safety-critical requirements specification and can automatically verify whether the security features meet the security requirements.

Key words: UMLsec, security feature, verification

中图分类号: