基于威胁建模的IC卡互联网终端安全问题定义方法

A Method of the Security Problem Definition on the IC Card International Terminal Based on the Threat Modeling

  • 摘要: 作为通用评估准则(CC)重要内容的安全目标,其有效性很大程度上依赖于对安全问题的准确定义,但在安全问题定义的过程中缺少必要的模型方法.为了减少安全问题定义的主观性,本文以支持移动支付应用的IC卡互联网终端产品为研究对象,提出以软件安全开发生命周期(SDL)威胁建模过程和威胁树分析为手段定义威胁的方法,并对安全问题的其他内容的定义方法和注意事项进行了说明,为后续全面准确进行安全目标安全对策的提出打下基础.

     

    Abstract: As the most important document, the validity of the security target is mostly dependent on the accuracy of security problem definition. However there is no necessary model and method in the security problem definition process. To reduce the subjectivity, taking IC card international terminal production applied in the online payment as the research object, a method of the threat definition was proposed based on the threat modeling method of the security development lifecycle (SDL) and threat tree analyzing. Furthermore, the definition method and considerations of other contents in security problem definition were illustrated. This paper will lay a foundation for the proposal of accurate security countermeasures in security target.

     

/

返回文章
返回