A case study in applying common criteria to development process to improve security of software products

Sang Ho Kim, Choon Seong Leem

Research output: Contribution to journalArticle

Abstract

IT Security evaluation based on Common Criteria (CC, ISO/IEC 15408), international standard for evaluation of security properties of IT products and systems, requires evaluation deliverables such as development and operational documents of TOE (Target of Evaluation) according to EAL (Evaluation Assurance Level). As most developers commonly prepare evaluation deliverables after their products have been developed, additional costs and time have been invested to be ready for evaluation evidences in reverse-engineering. But CC does not provide any methodological support to prepare evaluation deliverables, and furthermore, related work is not sufficient. In this paper, we present how CC applies to development process to improve security of their products and reduce the time and costs to make IT security evaluation. We demonstrate our idea by means of case study - developing MTOS 7.5, security enhanced UNIX-like operating system based on BSD 4.4 according to EAL3 in CC.

Original languageEnglish
Pages (from-to)1069-1077
Number of pages9
JournalLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume3043
Publication statusPublished - 2004 Dec 1

Fingerprint

Development Process
UNIX
Software
Reverse engineering
Computer operating systems
Evaluation
Costs
Reverse Engineering
Operating Systems
Sufficient
Target
Demonstrate

All Science Journal Classification (ASJC) codes

  • Theoretical Computer Science
  • Computer Science(all)

Cite this

@article{cc688a230ab24ee290fdd18e14cdd1dc,
title = "A case study in applying common criteria to development process to improve security of software products",
abstract = "IT Security evaluation based on Common Criteria (CC, ISO/IEC 15408), international standard for evaluation of security properties of IT products and systems, requires evaluation deliverables such as development and operational documents of TOE (Target of Evaluation) according to EAL (Evaluation Assurance Level). As most developers commonly prepare evaluation deliverables after their products have been developed, additional costs and time have been invested to be ready for evaluation evidences in reverse-engineering. But CC does not provide any methodological support to prepare evaluation deliverables, and furthermore, related work is not sufficient. In this paper, we present how CC applies to development process to improve security of their products and reduce the time and costs to make IT security evaluation. We demonstrate our idea by means of case study - developing MTOS 7.5, security enhanced UNIX-like operating system based on BSD 4.4 according to EAL3 in CC.",
author = "Kim, {Sang Ho} and Leem, {Choon Seong}",
year = "2004",
month = "12",
day = "1",
language = "English",
volume = "3043",
pages = "1069--1077",
journal = "Lecture Notes in Computer Science",
issn = "0302-9743",
publisher = "Springer Verlag",

}

TY - JOUR

T1 - A case study in applying common criteria to development process to improve security of software products

AU - Kim, Sang Ho

AU - Leem, Choon Seong

PY - 2004/12/1

Y1 - 2004/12/1

N2 - IT Security evaluation based on Common Criteria (CC, ISO/IEC 15408), international standard for evaluation of security properties of IT products and systems, requires evaluation deliverables such as development and operational documents of TOE (Target of Evaluation) according to EAL (Evaluation Assurance Level). As most developers commonly prepare evaluation deliverables after their products have been developed, additional costs and time have been invested to be ready for evaluation evidences in reverse-engineering. But CC does not provide any methodological support to prepare evaluation deliverables, and furthermore, related work is not sufficient. In this paper, we present how CC applies to development process to improve security of their products and reduce the time and costs to make IT security evaluation. We demonstrate our idea by means of case study - developing MTOS 7.5, security enhanced UNIX-like operating system based on BSD 4.4 according to EAL3 in CC.

AB - IT Security evaluation based on Common Criteria (CC, ISO/IEC 15408), international standard for evaluation of security properties of IT products and systems, requires evaluation deliverables such as development and operational documents of TOE (Target of Evaluation) according to EAL (Evaluation Assurance Level). As most developers commonly prepare evaluation deliverables after their products have been developed, additional costs and time have been invested to be ready for evaluation evidences in reverse-engineering. But CC does not provide any methodological support to prepare evaluation deliverables, and furthermore, related work is not sufficient. In this paper, we present how CC applies to development process to improve security of their products and reduce the time and costs to make IT security evaluation. We demonstrate our idea by means of case study - developing MTOS 7.5, security enhanced UNIX-like operating system based on BSD 4.4 according to EAL3 in CC.

UR - http://www.scopus.com/inward/record.url?scp=35048893943&partnerID=8YFLogxK

UR - http://www.scopus.com/inward/citedby.url?scp=35048893943&partnerID=8YFLogxK

M3 - Article

VL - 3043

SP - 1069

EP - 1077

JO - Lecture Notes in Computer Science

JF - Lecture Notes in Computer Science

SN - 0302-9743

ER -