Deploying security-critical systems requires assurance cases to demonstrate compliance with security requirements, as increasingly mandated by security standards. Building these cases with rigorous arguments and evidence is essential, yet gathering sufficient evidence post-deployment is often challenging, costly, and time-consuming. Security argument patterns aid in reuse, highlighting the need for tools that simplify their definition and application. This paper presents a methodology supported by a domain-specific modeling language (DSML) to create, analyze, and apply security argument patterns for constructing security cases.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Tool Support Methodology for Creating Security Cases Using Argument Patterns

  • Marwa Zeroual,
  • Brahim Hamid,
  • Morayo Adedjouma,
  • Jason Jaskolka

摘要

Deploying security-critical systems requires assurance cases to demonstrate compliance with security requirements, as increasingly mandated by security standards. Building these cases with rigorous arguments and evidence is essential, yet gathering sufficient evidence post-deployment is often challenging, costly, and time-consuming. Security argument patterns aid in reuse, highlighting the need for tools that simplify their definition and application. This paper presents a methodology supported by a domain-specific modeling language (DSML) to create, analyze, and apply security argument patterns for constructing security cases.