A novel method of security requirements development integrated common criteria

Lei Yin, Fang-Liang Qiu · 2010

A tri-stages security requirements engineering development model, which includes early-stage security requirements modeling, security policy and late-stage security requirements modeling, is proposed to improve the traditional security requirements modeling method. An extended framework, which defines new security flaw node, threat means node and elimination link, is proposed to identify the security objectives correctly and describe early-stage security requirements entirely. A method of defining security strategy formally is proposed to express security environment, avoid the conflicts and reduce the complexities of security rules. A kind of requirements modeling language CC-UML, which constructed by Conservative Extension of UML Metamodel, is proposed to integrate the CC functional requirements and late-stage security requirements seamlessly.

Read the paper · More papers on PaperTik