Abstract:
As the most important document, the validity of the security target is mostly dependent on the accuracy of security problem definition. However there is no necessary model and method in the security problem definition process. To reduce the subjectivity, taking IC card international terminal production applied in the online payment as the research object, a method of the threat definition was proposed based on the threat modeling method of the security development lifecycle (SDL) and threat tree analyzing. Furthermore, the definition method and considerations of other contents in security problem definition were illustrated. This paper will lay a foundation for the proposal of accurate security countermeasures in security target.