DocumentCode :
2058966
Title :
Introducing Vulnerability Awareness to Common Criteria´s Security Targets
Author :
Ardi, Shanai ; Shahmehri, Nahid
Author_Institution :
Dept. of Comput. & Inf. Sci., Linkopings Univ., Linkoping, Sweden
fYear :
2009
fDate :
20-25 Sept. 2009
Firstpage :
419
Lastpage :
424
Abstract :
Security of software systems has become one of the biggest concerns in our everyday life, since software systems are increasingly used by individuals, companies and governments. One way to help software system consumers gain assurance about the security measures of software products is to evaluate and certify these products with standard evaluation processes. The Common Criteria (ISO/IEC 15408) evaluation scheme is a standard that is widely used by software vendors. This process does not include information about already known vulnerabilities, their attack data and lessons learned from them. This has resulted in criticisms concerning the accuracy of this evaluation scheme since it might not address the areas in which actual vulnerabilities might occur. In this paper, we present a methodology that introduces information about threats from vulnerabilities to Common Criteria documents. Our methodology improves the accuracy of the Common Criteria by providing information about known vulnerabilities in Common Criteria´s security target. Our methodology also provides documentation about how to fulfill certain security requirements, which can reduce the time for evaluation of the products.
Keywords :
DP industry; distributed databases; security of data; software standards; Common Criteria evaluation scheme; ISO/IEC 15408; software products; software systems security; software vendors; standard evaluation processes; vulnerability awareness; Data security; Gain measurement; Government; IEC standards; ISO standards; Information security; Measurement standards; Software measurement; Software standards; Software systems; Common Criteria; security activity graph; security target; vulnerability cause graph; vulnerability cause mitigation; vulnerability modeling;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Software Engineering Advances, 2009. ICSEA '09. Fourth International Conference on
Conference_Location :
Porto
Print_ISBN :
978-1-4244-4779-4
Electronic_ISBN :
978-0-7695-3777-1
Type :
conf
DOI :
10.1109/ICSEA.2009.67
Filename :
5298872
Link To Document :
بازگشت