Software running security measurement and estimation method based on network environment

A software security and network environment technology, applied in the field of network information security analysis and evaluation, can solve problems such as poor pertinence, lack of test basis, lack of test basis, etc., and achieve the effect of good scalability, flexible evaluation method and objective evaluation

CN102799822BActive Publication Date: 2015-06-17CHINA INFORMATION TECH SECURITY EVALUATION CENT
4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Publication Date
2015-06-17

Smart Images

  • Figure 1
    Figure 1
  • Figure 2
    Figure 2
  • Figure 3
    Figure 3
Patent Text Reader

Abstract

The invention discloses a software running security measurement and estimation method based on a network environment, and belongs to a network information security analysis and estimation technology. The method comprises the following steps of: constructing a measurement system, namely selecting a software security estimation index; performing threat modeling, namely modeling a threat of software under the network environment; and estimating the security of the software, namely performing security estimation on the software facing the threat under the network environment according to the estimation index through a software security estimation method based on reliability, a software security estimation method based on bug and a software security estimation method based on risk. The step of constructing the measurement system also comprises a substep of selecting the completeness, the non-repudiation, the confidentiality, the authorization, the availability and the identity checkability as the software security estimation indexes. By the method, the security bug and the risk of the software can be estimated in advance, so that a function and security module of the software can be immediately adjusted, and dangerous events can be effectively controlled and prevented.
Need to check novelty before this filing date? Find Prior Art

Description

technical field

[0001] The present invention relates to network information security analysis and assessment technology, and more specifically, to a software security assessment method in a network environment. Background technique

[0002] Nowadays, the software system under the network environment has penetrated into various fields such as the national economy, national defense, and social life. It has changed people's traditional production and lifestyle, and has become an indispensable necessity for human society. On the one hand, people's dependence on software is getting higher and higher, making software systems and functions more and more complex; Quality is becoming more and more difficult, such as system attacks and failures caused by software vulnerabilities, defects and failures, software system paralysis caused by instantaneous mutations in the number of concurrent users of the system, and privacy leaks caused by malicious behaviors of rogue software. Hidden da...

Examples

Embodiment Construction

[0022] In order to make the above objects, features and advantages of the present invention more comprehensible, the present invention will be further described in detail below in conjunction with the accompanying drawings and specific embodiments.

[0023] refer to figure 1 , figure 1 It is a flow chart of the steps of the software security evaluation embodiment in the network environment of the present invention, including the following steps: step S110 of establishing a measurement system, selecting software security evaluation indicators; threat modeling step S120, modeling the threats faced by the software in the network environment ; Software security assessment step S130, based on the assessment indicators, use the reliability-based software security assessment method, the vulnerability-based software security assessment method and the risk-based software security assessment method to perform security assessment on software facing threats in the network environment . ...