An Ontology Based Information Security Requirements Engineering Framework

被引:0
|
作者
Chikh, Azeddine [2 ]
Abulaish, Muhammad [1 ,3 ]
Nabi, Syed Irfan [1 ,3 ,4 ]
Alghathbar, Khaled [1 ,2 ,3 ]
机构
[1] King Saud Univ, Ctr Excellence Informat Assurance, Riyadh, Saudi Arabia
[2] King Saud Univ, Coll Comp & Informat Sci, Riyadh, Saudi Arabia
[3] King Saud Univ, Ctr Excellence Informat Assurance, Riyadh, 11451, Saudi Arabia
[4] Inst Bus Adm, Fac Comp Sci, Karachi, Pakistan
关键词
Information security; software requirements engineering; Software requirements specification;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software Requirement Specification (SRS) is frequently evolving to reflect requirements change during project development. Therefore, it needs enhancement to facilitate its authoring and reuse. This paper proposes a framework for building a part of SRS related to information security requirements (ISRs) using ontologies. Such a framework allows ensuring ISRs traceability and reuse. The framework uses three kinds of generic ontologies as a solution to this problem - software requirement ontology, application domain ontology, information security ontology. We propose to enhance SRS by associating the ISR with specific entities within ontologies. We aim to facilitate a semantic-based interpretation of ISRs by restricting their interpretation through the three previous ontologies. Semantic form is used to improve our ability to create, manage, and maintain ISRs. We anticipate that the proposed framework would be very helpful for requirements engineers to create and understand the ISRs.
引用
收藏
页码:139 / +
页数:3
相关论文
共 50 条
  • [21] A vulnerability-centric requirements engineering framework: analyzing security attacks, countermeasures, and requirements based on vulnerabilities
    Golnaz Elahi
    Eric Yu
    Nicola Zannone
    [J]. Requirements Engineering, 2010, 15 : 41 - 62
  • [22] A vulnerability-centric requirements engineering framework: analyzing security attacks, countermeasures, and requirements based on vulnerabilities
    Elahi, Golnaz
    Yu, Eric
    Zannone, Nicola
    [J]. REQUIREMENTS ENGINEERING, 2010, 15 (01) : 41 - 62
  • [23] Ontology-based Negotiation of Security Requirements in Cloud
    Liccardo, Loredana
    Rak, Massimiliano
    Di Modica, Giuseppe
    Tomarchio, Orazio
    [J]. 2012 FOURTH INTERNATIONAL CONFERENCE ON COMPUTATIONAL ASPECTS OF SOCIAL NETWORKS (CASON), 2012, : 192 - 197
  • [24] Information Security Engineering: a Framework for Research and Practices
    Li, M.
    Tang, M.
    [J]. INTERNATIONAL JOURNAL OF COMPUTERS COMMUNICATIONS & CONTROL, 2013, 8 (04) : 578 - 587
  • [25] An Extended Ontology for Security Requirements
    Massacci, Fabio
    Mylopoulos, John
    Paci, Federica
    Tun, Thein Thun
    Yu, Yijun
    [J]. ADVANCED INFORMATION SYSTEMS ENGINEERING WORKSHOPS, 2011, 83 : 622 - +
  • [26] An ontology-based approach to engineering ethicality requirements
    Guizzardi, Renata
    Amaral, Glenda
    Guizzardi, Giancarlo
    Mylopoulos, John
    [J]. SOFTWARE AND SYSTEMS MODELING, 2023, 22 (06): : 1897 - 1923
  • [27] An ontology-based approach to engineering ethicality requirements
    Renata Guizzardi
    Glenda Amaral
    Giancarlo Guizzardi
    John Mylopoulos
    [J]. Software and Systems Modeling, 2023, 22 : 1897 - 1923
  • [28] An Ontology-Based Approach to the Agile Requirements Engineering
    Murtazina, Marina
    Avdeenko, Tatiana
    [J]. PERSPECTIVES OF SYSTEM INFORMATICS (PSI 2019), 2019, 11964 : 205 - 213
  • [29] Ontology-based multiperspective requirements traceability framework
    Assawamekin, Namfon
    Sunetnanta, Thanwadee
    Pluempitiwiriyawej, Charnyote
    [J]. KNOWLEDGE AND INFORMATION SYSTEMS, 2010, 25 (03) : 493 - 522
  • [30] Ontology based Framework for DetectingAmbiguities in Software Requirements Specification
    Bhatia, M. P. S.
    Kumar, Akshi
    Beniwal, Rohit
    [J]. PROCEEDINGS OF THE 10TH INDIACOM - 2016 3RD INTERNATIONAL CONFERENCE ON COMPUTING FOR SUSTAINABLE GLOBAL DEVELOPMENT, 2016, : 3572 - 3575