摘要
文章分析了在等级保护过程中进行威胁建模的必要性,结合《实施指南》提出一种基于威胁建模的软件安全需求分析方法,通过威胁一攻击图(TAG)评估攻击,根据评估结果及《基本要求》确定应对方案,将等级保护思想融入到软件安全设计阶段中,使得应对方案能更高效地改进软件设计以增强软件安全性,并通过实际案例对本方法进行了验证。
In this paper, the necessity of threat modeling during the process of information system classified security protection is analysed. Combined with the "Implementation Guide", a method of software security requirements analysis, which evaluated the risk by generating threat-attack graph and figures out the responses based on the assessment and the "basic requirements ", is proposed. By applying this method, the idea of information classified security protection is introduced into the software design phase, which facilitates the development of software security. A case is given to test the validity of the method.
出处
《信息网络安全》
2011年第9期101-103,共3页
Netinfo Security
关键词
等级保护
软件安全
威胁建模
information classified
security protection
software security
threat modeling