论文标题
安全保证案件 - 新兴方法的艺术状况
Security Assurance Cases -- State of the Art of an Emerging Approach
论文作者
论文摘要
安全保证案例(SAC)是用于推理系统安全属性的结构性论证的一种形式。在成功采用保证案件的安全案件之后,SAC近年来正在获得大量的吸引力,尤其是在安全至关重要的行业(例如汽车),在这种行业中,越来越多的压力符合多种安全标准和法规。因此,在过去的十年中,SAC领域的研究蓬勃发展,正在研究不同的方法。为了系统化这一积极的研究领域,我们对SAC现有的学术研究进行了系统的文献综述(SLR)。我们的审查导致了51篇论文的深入分析和比较。我们的结果表明,尽管有许多论文讨论了安全保证案件的重要性及其使用情况,但对于对从业者的具体支持,关于如何构建和维护SAC,文献仍然不成熟。更重要的是,即使有一些方法可用,它们的验证和工具支持仍然缺乏。
Security Assurance Cases (SAC) are a form of structured argumentation used to reason about the security properties of a system. After the successful adoption of assurance cases for safety, SACs are getting significant traction in recent years, especially in safety-critical industries (e.g., automotive), where there is an increasing pressure to be compliant with several security standards and regulations. Accordingly, research in the field of SAC has flourished in the past decade, with different approaches being investigated. In an effort to systematize this active field of research, we conducted a systematic literature review (SLR) of the existing academic studies on SAC. Our review resulted in an in-depth analysis and comparison of 51 papers. Our results indicate that, while there are numerous papers discussing the importance of security assurance cases and their usage scenarios, the literature is still immature with respect to concrete support for practitioners on how to build and maintain a SAC. More importantly, even though some methodologies are available, their validation and tool support is still lacking.