首页 | 本学科首页   官方微博 | 高级检索  
     

通用标准CC的研究与实现
引用本文:朱岩,杨永田,张玉清,冯登国.通用标准CC的研究与实现[J].小型微型计算机系统,2005,26(7):1174-1178.
作者姓名:朱岩  杨永田  张玉清  冯登国
作者单位:1. 哈尔滨工程大学,计算机科学与技术学院,黑龙江,哈尔滨,150001;中国科学院,国家计算机网络入侵防范中心,北京,100049
2. 哈尔滨工程大学,计算机科学与技术学院,黑龙江,哈尔滨,150001
3. 中国科学院,国家计算机网络入侵防范中心,北京,100049
基金项目:国家“八六三”计划项目(2002AA142151)资助
摘    要:随着计算机技术及Internet的不断发展,如何保证信息系统安全成为一个重要课题.针对这个问题,设计实现了基于信息技术安全性评估准则(通用标准)的系统评估方法和软件.首先在分析通用标准结构的基础上,设计了安全功能和保证要求的体系结构;接着针对保护轮廓和安全目标这两个通用标准的核心文档进行了分析与设计,并指出了文档结构中的内在联系;然后提出了针对标准结构和其内在关联应完成的评估要素;最后给出了评估系统的设计和实现.通过实际保护轮廓和软件产品的安全目标实例分析表明本文所提出的评估方法和系统能够指导信息系统的评估和实践.

关 键 词:通用标准  安全评估  保护轮廓  安全目标
文章编号:1000-1220(2005)07-1174-05

Research and Implementation of Common Criteria
ZHU Yan,YANG Yong-tian,ZHANG Yu-qing,FENG Deng-guo.Research and Implementation of Common Criteria[J].Mini-micro Systems,2005,26(7):1174-1178.
Authors:ZHU Yan  YANG Yong-tian  ZHANG Yu-qing  FENG Deng-guo
Affiliation:ZHU Yan 1,2,YANG Yong-tian 1,ZHANG Yu-qing 2,FENG Deng-guo 2 1
Abstract:With the development of computer technology and Internet, It becomes a very important issue how to assure information system security. To the question, the paper presents a system evaluation method and software based on the Evaluation Criteria for Information Technology Security (Common Criteria). At first, the architecture of security function and assurance requirement is designed with respect to Common Criteria structure; then analysis and design are applied to the core documents of Common Criteria, Protection Profile and Security Target, and cross relationships among them is specified. Moreover, essentials evaluation properties are presented on the basis of criteria structures and cross relationships. Finally a practical evaluation system are proposed and achieved. According to Protection Profiles and Security Targets in actual software product, the experimental results demonstrate that the proposed evaluation method and system can instruct information system evaluation and practice.
Keywords:common criteria  security evaluation  protect profile  security target
本文献已被 CNKI 维普 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号