论文标题

通过角色确定隐性漏洞作为目标模型

Identifying Implicit Vulnerabilities through Personas as Goal Models

论文作者

Faily, Shamal, Iacob, Claudia, Ali, Raian, Ki-Aries, Duncan

论文摘要

当在需求过程和工具中使用时,角色有可能确定因用户期望和系统目标之间的不对准而导致的漏洞。但是,通常,由于角色和系统目标是由不同的思维方式,不同的团队以及出于不同的目的来捕获的,因此这种潜力无法实现。如果将角色视为目标模型,那么利益相关者可能会更容易看到其目标的含义,并且设计师将这些模型的创建和分析纳入更广泛的RE链链中。本文概述了一种通过将角色作为社会目标模型的角色将用户和系统目标找到隐性漏洞的工具支持方法。我们通过案例研究说明了这种方法,该案例研究确定了以前基于人类行为的隐藏漏洞。

When used in requirements processes and tools, personas have the potential to identify vulnerabilities resulting from misalignment between user expectations and system goals. Typically, however, this potential is unfulfilled as personas and system goals are captured with different mindsets, by different teams, and for different purposes. If personas are visualised as goal models, it may be easier for stakeholders to see implications of their goals being satisfied or denied, and designers to incorporate the creation and analysis of such models into the broader RE tool-chain. This paper outlines a tool-supported approach for finding implicit vulnerabilities from user and system goals by reframing personas as social goal models. We illustrate this approach with a case study where previously hidden vulnerabilities based on human behaviour were identified.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源