{"title":"Automated Reasoning towards Quantitative Security Assurance","authors":"Zhengshu Zhou, Qiang Zhi, Shuichiro Yamamoto, Zilong Liang","doi":"10.1109/ICSESS47205.2019.9040823","DOIUrl":null,"url":null,"abstract":"System security assurance has become one of the most important research directions in software engineering and requirement engineering. To date, a lot of approaches have been proposed to conduct system security assurance. However, in these existing approaches, the constraint conditions of security assurance are rarely mentioned. In software engineering domain, constraint is a critical factor that can affect the success or failure of the engineering project, and thus the practicability of these approaches may be called in question. In order to resolve this problem, this paper proposes a new security assurance method that allows engineers to give consideration to both contribution attributes and cost attributes for security objectives during system architecture design process. In addition, a recursive algorithm is proposed and implemented to realize automated reasoning for developing security assurance cases.","PeriodicalId":203944,"journal":{"name":"2019 IEEE 10th International Conference on Software Engineering and Service Science (ICSESS)","volume":"162 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2019 IEEE 10th International Conference on Software Engineering and Service Science (ICSESS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICSESS47205.2019.9040823","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
System security assurance has become one of the most important research directions in software engineering and requirement engineering. To date, a lot of approaches have been proposed to conduct system security assurance. However, in these existing approaches, the constraint conditions of security assurance are rarely mentioned. In software engineering domain, constraint is a critical factor that can affect the success or failure of the engineering project, and thus the practicability of these approaches may be called in question. In order to resolve this problem, this paper proposes a new security assurance method that allows engineers to give consideration to both contribution attributes and cost attributes for security objectives during system architecture design process. In addition, a recursive algorithm is proposed and implemented to realize automated reasoning for developing security assurance cases.