:::

詳目顯示

回上一頁
題名:以量測為基礎的軟體安全風險改善作業
書刊名:創新與管理
作者:賴森堂 引用關係
作者(外文):Lai, Sen-tarng
出版日期:2008
卷期:5:1
頁次:頁83-100
主題關鍵詞:軟體安全性安全漏洞安全風險風險因子量測模式Software securitySecurity holesSecure riskRisk factorMeasurement model
原始連結:連回原系統網址new window
相關次數:
  • 被引用次數被引用次數:期刊(0) 博士論文(0) 專書(0) 專書論文(0)
  • 排除自我引用排除自我引用:0
  • 共同引用共同引用:0
  • 點閱點閱:16
駭客入侵、病毒攻擊與系統本身的安全漏洞持續危害正常運作的軟體系統,使得軟體系統的安全性受到嚴重的考驗。在軟體開發過程中的安全風險問題,受到技術、管理及制度等層面的衝擊,融入產品中的安全缺失不易被及時發現,因此,一旦問題浮現後,安全漏洞所造成危害與損失,將形成難以預期的危機。為此,如何運用安全風險管理降低安全漏洞與缺失,成為值得深入探究的課題。軟體開發前的安全風險評估,是降低安全風險的關鍵,適時標示出軟體開發可能發生的安全風險,才能針對安全風險提出具體的改善措施與監控作業,進而降低軟體安全風險,提昇軟體系統的安全性。本文針對技術、管理及制度等層面的安全風險因子進行探討與蒐集,且提出一套以量測為基礎的軟體安全風險改善作業(SEcurity Risk Improvement Operation; SERIO),協助軟體開發過程中,找出潛在的安全風險,且衍生出安全風險的改善與監控作業,有效提高軟體系統的安全性。
Hacker invaded, virus attacked and system security vulnerabilities endanger normal operation of software system and cause software system security suffer serious test. The security risk issue is impacted by such aspects as the technology, management and system, etc. in software development. It is difficult to find and modify the security lacks of software system in time, so, once after the question appears, security holes and lacks may cause unexpected result. For this, how to use security risk management to reduce security hole and lack, become the subject that is worth probing into thoroughly. The security risk assessment before software development is the key to reducing security holes and lacks. Identify the security risk that software development may take place, could put forward the concrete improvement measure and control operation to the security risk, and then reduce the security risk and promote the security of the software system. This paper carries on the discussion and collects to the security risk factor of such aspects as the technology, management and system, etc. And propose a Measurement-based Improvement Operation for Software Security Risk (SEcurity Risk Improvement Operation; SERIO). Applying the SERIO to software development, can help to find out the potential security risk, derive out improvement of the security risk and control operation, and increase the security of the software system effectively.
期刊論文
1.Apvrille, A.、Pourzandi, M.(2005)。Secure Software Development by Example。IEEE Security & Privacy,3(4),10-17。  new window
2.Davis, N.、Humphrey, W.、Redwine, S. T. Jr.、Zibulski, G.、McGraw, G.(2004)。Processes for Producing Secure Software。IEEE Security & Privacy,2(3),18-25。  new window
3.McGraw, G.(2004)。Software Security。IEEE Security and Privacy,2(2),80-83。  new window
4.Cowan, C.(2003)。Software Security for Open-Source Systems。IEEE Security & Privacy,1(1),38-45。  new window
會議論文
1.Lai, S. T.、Yang, C. C.(1998)。A Software Metric Combination Model for Software Reuse。1998 Asia-Pacific Software Engineering Conference,70-77。  new window
2.賴森堂(2007)。安全軟體建制基礎--軟體安全特性架構之研究。2007數位科技與創新管理研討會。華梵大學。  延伸查詢new window
圖書
1.Pressman, R. S.(2004)。Software Engineering: A Practitioner's Approach。McGraw-Hill。  new window
2.Fairly, Richard(1985)。Software Engineering Concepts。McGraw-Hill, Inc.。  new window
3.Galin, D.(2004)。Software Quality Assurance。Addison-Wesley。  new window
4.Hall, A.、Chapman, Roderick(2002)。Correctness by Construction: Developing a Commercial Secure System。IEEE Software。  new window
5.Howard, M.、Le Blanc, D.(2002)。Writing Secure Code。Microsoft Press。  new window
6.Viega, J.、McGraw, G.(2002)。Building Secure Software。Addison-Wesley。  new window
7.Bishop, M.(2003)。Computer Security: Art and Science。Boston, MA:Addison-Wesley。  new window
8.Leveson, N. G.(1995)。Safeware: System Safety and Computers。Addison-Wesley。  new window
9.Conte, S. D.、Dunsmore, H. E.、Shen, V. Y.(1986)。Software Engineering Metrics and Models。Menlo Park。  new window
10.Fenton, N. E.(1991)。Software Metrics: A Rigorous Approach。Chapman & Hall。  new window
11.Boehm, B. W.(1981)。Software Engineering Economics。Englewood Cliffs, NJ:Prentice-Hall。  new window
12.Deutsch, M. S.、Willis, R. R.(1988)。Software Quality Engineering: A Total Technical and Management Approach。New Jersey:Prentice-Hall Inc.。  new window
13.McGraw, G.(2006)。Software Security-Building Security In。Addison-Wesley。  new window
單篇論文
1.(1988)。ISO/IEC: FCD 9126-1.2: Information Technology - Software Product Quality. Part I: Quality Model。  new window
 
 
 
 
第一頁 上一頁 下一頁 最後一頁 top