期刊文献+

J2EE应用软件的架构安全评估方法 被引量:9

Security Evaluation Method for the Architecture of J2EE Applications
下载PDF
导出
摘要 为了识别J2EE架构设计中潜在风险以及评估J2EE安全机制的实施程度,提出了一种基于组件安全属性的J2EE架构安全性评估方法。该方法关注于架构安全机制的实施力度,将架构的安全性细化到组件层,并使用安全属性树描述组件的安全机制,从而进行评估。在评估时,首先依据J2EE层次和组件功能对组件进行分类,然后采用层次分析法和模糊评价法计算组件安全性评估要素,最后综合组件安全性要素得出J2EE设计的安全性结论。实验表明该方法提高了评估效率,使得J2EE架构安全性评估过程更具客观性和精确性。 In order to identify potential risks of J2EE architecture and assess the implementation of J2EE security mechanisms, this paper presents a quantitative J2EE security evaluation method based on the security of compo-nents. The method focuses on efforts to architecture security mechanism through refining the security of architecture to component level and describing component security mechanism by security tree. In this process, components of J2EE architecture are classified and their security measures are identified according to the component function and J2EE level. Then, an integration process of analytic hierarchy process (AHP) and fuzzy evaluation analysis is used to consider quantitative and qualitative factors in evaluating the security of components to obtain security conclu-sions of architecture. The experiments show that this method can not only improve the evaluation efficiency, but also make the security evaluation process more objective and accurate.
出处 《计算机科学与探索》 CSCD 2014年第5期572-581,共10页 Journal of Frontiers of Computer Science and Technology
基金 国家自然科学基金Nos.91118003 61272106/F020208~~
关键词 安全性评估 组件 安全属性树形模型 J2EE J2EE security evaluation component security tree model
  • 相关文献

参考文献3

二级参考文献18

  • 1SHENGJinfang CHENSongqiao WANGBin.COTS Evaluation and Selection Based on Requirements Decomposition[J].Chinese Journal of Electronics,2005,14(1):62-67. 被引量:8
  • 2JosephJBambara著 刘尧译.J2EE技术内幕[M].北京:机械工业出版社,2002..
  • 3[1]R S Pressman. Software Engineering:A Practitioner's Approach[M].5th ed,Tsinghua University Press,2001:346~347
  • 4[2]L G Williams,C U Smith. Performance Evaluation of Software Architectures[C].In:Proceedings of the First International Workshop on Software and Performance WOSP 98 Santa Fe,New Mexico,USA,1998:164~177
  • 5[3]S Balsamo et al.An Approach to Performance Evaluation of Software Architectures[C].In :Proceedings of the First International Workshop on Software and Performance WOSP 98,Santa Fe,New Mexico,USA,1998:178~189
  • 6[4]D Petriu et al. Architecture-based Performance Analysis Applied to a Telecommunication System[J].IEEE Trans Software Eng,2000;26(11):1049~1065
  • 7[5]D A Menasce',H Gomaa. A Method for Design and Performance Modeling of Client/Server Systems[J].IEEE Trans Software Eng,2000;26(11 ):1066~1085
  • 8[6]S Gilmore et al. An Efficient Algorithm for Aggregation PEPA Models[J].IEEE Trans Software Eng,2001 ;27(5) :449~464
  • 9PRAVIN V TULACHAN.EJB2.0组件开发指南[M].肖国尊译.北京:清华大学出版社,2002.
  • 10Floyd Marinescu.EJB设计模式[M].北京:机械工业出版社,2004

共引文献41

同被引文献75

引证文献9

二级引证文献25

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部