90 likes | 205 Views
The DIAMONDS Security Information Model. A. Vouffo (Fraunhofer FOKUS). Introduction. ETSI TVRA [ TS 102 165- 1 V4.2.3 (2011 - 03 )] provides an information model for security
E N D
The DIAMONDS Security Information Model A. Vouffo (Fraunhofer FOKUS)
Introduction • ETSI TVRA [TS 102 165- 1 V4.2.3 (2011 - 03)]provides an informationmodelforsecurity • SINTEF reuseselementsofthe ETSI TVRA informationmodel in its CORAS metamodelandextendsitwithriskmodellingconcepts • Common Criteriacombineselementsof ETSI TVRA andintroducestestingconcepts. • Howevertestingis not specificallyaddressedbyanyofthosemodels • The DIAMONDS projectisworking on Model-based Security Testing • Model-basedsecurity design • Model-basedtesting • An informationmodelcombining model-basedtestingand model-basedsecurity design canbecommongroundfor model-basedsecuritytesting
Goals • Toclarifyterminologyanddefineconcepts • Toputconceptsfromthe different aspectsofsecurity (System design, security design, riskanalysisandtesting) in relationshiptoeachother. • Toprovide a commonconceptspacefortoolstargetting different aspectsofthemethod.
Summary and Outlook • The DIAMONDS informationmodelreusesconceptsalreadydefinedby TVRA, SINTEF and Common Criteria • Focus is on testingconceptsandrelationshipwithothersecurityconcepts • The model will provide a commonbaseforthe DIAMONDS project‘ssecuritytestingintegrationplatform • The modelis not completelydefinedyet • Testinginformationmodelisready • Security informationmodelisready • Genericsystem design informationmodelisready • Linking ofconceptswitheachotherhasbeenstarted, but yettobecompleted