• DocumentCode
    130822
  • Title

    Aspect-oriented reuse mechanism for security targets and protection profiles

  • Author

    Goto, Yasunori ; Huilin Chen ; Da Bao

  • Author_Institution
    Dept. of Inf. & Comput. Sci., Saitama Univ., Saitama, Japan
  • fYear
    2014
  • fDate
    27-29 June 2014
  • Firstpage
    161
  • Lastpage
    164
  • Abstract
    Common Criteria (CC) is an international standard for evaluation and certification of IT products. Although a security target (ST) is an important and central document used in the security evaluation process of CC, creating STs is not so easy task for most of software engineers. On the other hand, there are dependency relations among several elements of an ST and a protection profile (PP). Elements of an ST/PP are elements of mandatory contents of STs/PPs defined in CC part 1, e.g., security problems, security objectives, security requirements, and so on. If there is a same element in both an ST/PP and other ST/PP, then what to describe and how to describe elements that depend on the same element are probably similar. Such same element and its dependent elements are a cross-cutting concern among the STs/PPs. Although retrieving cross-cutting concerns among certified STs and PPs are useful for creation and evaluation of STs and PPs, it is difficult, not impossible, to do that because certified STs and PPs are published as PDF files. This paper presents an aspect-oriented reuse mechanism for STs and PPs to help creation and evaluation of STs. The paper also shows technical issues and current implementation of the mechanism.
  • Keywords
    aspect-oriented programming; security of data; software reusability; CC; IT products; ST; aspect-oriented reuse mechanism; common criteria; cross-cutting concern; dependency relations; international standard; protection profiles; security evaluation process; security objectives; security problems; security requirements; security targets; software engineers; Databases; IEC standards; ISO standards; Information security; Information technology;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Software Engineering and Service Science (ICSESS), 2014 5th IEEE International Conference on
  • Conference_Location
    Beijing
  • ISSN
    2327-0586
  • Print_ISBN
    978-1-4799-3278-8
  • Type

    conf

  • DOI
    10.1109/ICSESS.2014.6933536
  • Filename
    6933536