欢迎访问中国科学院大学学报,今天是
论文

一种改进的网络可生存需求分析方法

  • 孔(王莹) ,
  • 张玉清
展开
  • 中国科学院研究生院国家计算机网络入侵防范中心, 北京 100049

收稿日期: 2008-12-01

  修回日期: 2009-03-25

  网络出版日期: 2009-07-15

基金资助

国家自然科学基金项目(60573048,60773135,90718007)和国家高技术研究发展计划("863"计划)项目(2007AA01Z427,2007AA01Z450)资助 

An improved survivable network requirement analysis framework

  • KONG Ying ,
  • ZHANG Yu-Qing
Expand
  • National Computer Network Intrusion Protection Center, Graduate University of the Chinese Academy of Sciences, Beijing 100049, China

Received date: 2008-12-01

  Revised date: 2009-03-25

  Online published: 2009-07-15

摘要

提出一种改进的信息系统可生存需求分析框架ISNA(improved SNA). 在组件式开发模型中选择合适模型作为分析基础,避免了SNA(survivable network analysis)只能建立在重量级螺旋模型上的弊端. 增加可生存测试和故障攻击库等反馈措施有效解决需求的多变性问题,保障完备性. 最后用一个小型电子商务系统实例论证了ISNA能够更好地指导和改进系统设计和实现,增加系统的可生存能力.

关键词: SNA; 可生存性; 需求分析; ISNA

本文引用格式

孔(王莹) , 张玉清 . 一种改进的网络可生存需求分析方法[J]. 中国科学院大学学报, 2009 , 26(4) : 555 -562 . DOI: 10.7523/j.issn.2095-6134.2009.4.018

Abstract

An improved survivable network requirement analysis framework (ISNA) is proposed. It is required to choose the best suitable software development model as the framework basement from the component-oriented set, which avoids SNAs shortcoming with only one choice of heavy model named spiral. The feedback components, an embedded survivable test and fault-attack library, fix the requirements variability and guarantee its integrity. At last, we analyzed an e-business website with ISNA, proving that ISNA performs better at guiding systems implementation and improving its survivability.

参考文献


[1] Vickie R W. A definition for information system survivability //Proceedings of the 37th Hawaii Internal Conference on System Sciences (HICSS04). Los Alamitos, CA: IEEE CS Press, 2004: 2086-2096.

[2] Thayer R H, Dorfman M (Eds). Software requirements engineering
[M]. Los Alamitos, CA:IEEE Computer Society Press,1997.

[3] Linger R C, Mead N R, Lipson H F. Requirements definition for survivable network systems //Proceedings of Third International Conference on Requirements Engineering.Colorado Springs: IEEE CS Press, 1998: 14-23.

[4] Nancy R Mead. Requirements engineering for survivable systems
[M]. Pittsburgh, PA: Software Engineering Institute, Carnegie Mellon University, 2003. http://www.sei.cmu.edu/pub/documents/03.reports/pdf/03tn013.pdf.

[5] Ellison R J, Fisher D A, Linger R C. An approach to survivable systems //NATO IST Symposium on Protecting Information Systems in the 21st Century. 1999. http://www.sei.cmu.edu/community/easel/pdfs/nato1.pdf.

[6] Firesmith D G. Engineering security requirements
[J]. Journal of Object Technology, 2003. http://www.jot.fm/issues/issue_2003_01/column6/.

[7] Abrahamsson P, Salo O, Ronkainen J. Agile software development methods
[M]. Espoo: Review and Analysis VIT Publications 478, 2002.

[8] 李 匀.网络渗透测试——保护网络安全的技术、工具和过程
[M].北京:电子工业出版社,2007.

文章导航

/