The Scheme of Security Requirement Acquisition Based on Knowledge Graph

Yu Zhang, Xiaohong Li · 2020

Specifying security requirements (SR) during the requirement analysis phase is essential for enhancing system quality, especially for security-critical software systems. However, it is difficult and complex to analyze SRs in detail according to ISO/IEC 15408 (known as Common Criteria). In this paper, we propose a SR acquisition scheme based on knowledge graph (KG). In this scheme, some security concepts such as Security Threat, Organizational Security Policy (OSP), Security Objective, Evaluation Assurance Level (EAL), SR and their relationships are all represented in the KG. SRs can be acquired through knowledge reasoning after embedding KG into low dimensional space and training by using TransE model. To evaluate the KG-based scheme, our experiments are performed on certified Security Target (ST) documents provided by Common Criteria (CC). Experimental results show that more accurate SRs can be acquired through KG reasoning.

Read the paper · More papers on PaperTik