DocumentCode
2058966
Title
Introducing Vulnerability Awareness to Common Criteria´s Security Targets
Author
Ardi, Shanai ; Shahmehri, Nahid
Author_Institution
Dept. of Comput. & Inf. Sci., Linkopings Univ., Linkoping, Sweden
fYear
2009
fDate
20-25 Sept. 2009
Firstpage
419
Lastpage
424
Abstract
Security of software systems has become one of the biggest concerns in our everyday life, since software systems are increasingly used by individuals, companies and governments. One way to help software system consumers gain assurance about the security measures of software products is to evaluate and certify these products with standard evaluation processes. The Common Criteria (ISO/IEC 15408) evaluation scheme is a standard that is widely used by software vendors. This process does not include information about already known vulnerabilities, their attack data and lessons learned from them. This has resulted in criticisms concerning the accuracy of this evaluation scheme since it might not address the areas in which actual vulnerabilities might occur. In this paper, we present a methodology that introduces information about threats from vulnerabilities to Common Criteria documents. Our methodology improves the accuracy of the Common Criteria by providing information about known vulnerabilities in Common Criteria´s security target. Our methodology also provides documentation about how to fulfill certain security requirements, which can reduce the time for evaluation of the products.
Keywords
DP industry; distributed databases; security of data; software standards; Common Criteria evaluation scheme; ISO/IEC 15408; software products; software systems security; software vendors; standard evaluation processes; vulnerability awareness; Data security; Gain measurement; Government; IEC standards; ISO standards; Information security; Measurement standards; Software measurement; Software standards; Software systems; Common Criteria; security activity graph; security target; vulnerability cause graph; vulnerability cause mitigation; vulnerability modeling;
fLanguage
English
Publisher
ieee
Conference_Titel
Software Engineering Advances, 2009. ICSEA '09. Fourth International Conference on
Conference_Location
Porto
Print_ISBN
978-1-4244-4779-4
Electronic_ISBN
978-0-7695-3777-1
Type
conf
DOI
10.1109/ICSEA.2009.67
Filename
5298872
Link To Document