Method and apparatus for evaluating security and method and apparatus for supporting the making of security countermeasure
    1.
    发明授权
    Method and apparatus for evaluating security and method and apparatus for supporting the making of security countermeasure 失效
    评估安全性的方法和装置,支持制定安全对策的方法和装置

    公开(公告)号:US06971026B1

    公开(公告)日:2005-11-29

    申请号:US09628108

    申请日:2000-07-27

    摘要: A security support and evaluation system in accordance with the present invention accepts from an operator via an input unit 16, a first specification of a system to be evaluated and a second specification of each of the components constituting the system, and then retrieves data from a security countermeasure database 131 stored in an external storage unit 13 and reads out security countermeasures to be executed to each of the components of the specified system to be evaluated, and then displays on a display unit 17, the security countermeasures read out in correspondence with each of the components of the specified system to be evaluated, and then accepts from the operator via the input unit 16, information whether or not each of the security countermeasures is executed, and thereafter evaluates the state of security based on the information and displays evaluation results on the display unit 17.

    摘要翻译: 根据本发明的安全支持和评估系统经由输入单元16接收来自操作者的输入单元16,要评估的系统的第一指定和构成系统的每个组件的第二指定,然后从 存储在外部存储单元13中的安全对策数据库131,并读出要执行的要评估的指定系统的每个组件的安全对策,然后在显示单元17上显示与每个对应的读取的安全对策 的待评估的指定系统的组件,然后经由输入单元16从操作员接受,执行每个安全对策的信息,然后基于该信息评估安全状态并显示评估结果 在显示单元17上。

    Security system design supporting method
    2.
    发明授权
    Security system design supporting method 有权
    安全系统设计配套方法

    公开(公告)号:US07089581B1

    公开(公告)日:2006-08-08

    申请号:US09640016

    申请日:2000-08-17

    IPC分类号: G06F9/44

    CPC分类号: G06Q99/00

    摘要: A security system design supporting tool and method are disclosed, in which security requirements (PP) and security specifications (ST) used for designing a product or a system (TOE) based on CC requirements can be prepared efficiently and uniformly even by ordinary designers other than specialists. In a security system design supporting method, registered PPs and past PP/ST generation cases are so structured as to reuse and/or reference as templates, a draft is automatically generated, and the draft thus generated is additionally modified or corrected by partial automatic generation utilizing a database of past generation cases and partial case accumulated in the generation process thereof.

    摘要翻译: 公开了一种安全系统设计支持工具和方法,其中可以通过普通设计者等来准确地准确地准备基于CC要求的用于设计产品或系统(TOE)的安全要求(PP)和安全规范(ST) 比专家。 在安全系统设计支持方法中,登记的PP和过去的PP / ST生成案例被结构化为重用和/或引用作为模板,自动生成草案,并且通过部分自动生成来附加地修改或修正 利用过去世代案例的数据库和在其生成过程中累积的部分情况。