TY - JOUR
T1 - A case study in applying common criteria to development process of virtual private network
AU - Kim, Sang Ho
AU - Leem, Choon Seong
PY - 2004
Y1 - 2004
N2 - IT Security evaluation based on Common Criteria (CC, ISO/IEC15408), international standard for evaluation of security properties of IT products and systems, requires evaluation deliverables such as development and operational documents of TOE(Target of Evaluation) according to EAL(Evaluation Assurance Level). As most developers commonly prepare evaluation deliverables after their products have been developed, additional costs and time have been invested to be ready for evaluation evidences in reverse-engineering. But CC does not provide any methodological support to prepare evaluation deliverables, and furthermore, related work is not sufficient. In this paper, we present how Common Criteria apply to development process of VPN (Virtual Private Network). We demonstrate our idea by means of case study - developing RVPN V1.0 according to EAL4 in CC.
AB - IT Security evaluation based on Common Criteria (CC, ISO/IEC15408), international standard for evaluation of security properties of IT products and systems, requires evaluation deliverables such as development and operational documents of TOE(Target of Evaluation) according to EAL(Evaluation Assurance Level). As most developers commonly prepare evaluation deliverables after their products have been developed, additional costs and time have been invested to be ready for evaluation evidences in reverse-engineering. But CC does not provide any methodological support to prepare evaluation deliverables, and furthermore, related work is not sufficient. In this paper, we present how Common Criteria apply to development process of VPN (Virtual Private Network). We demonstrate our idea by means of case study - developing RVPN V1.0 according to EAL4 in CC.
UR - http://www.scopus.com/inward/record.url?scp=35048824933&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=35048824933&partnerID=8YFLogxK
U2 - 10.1007/978-3-540-24707-4_72
DO - 10.1007/978-3-540-24707-4_72
M3 - Article
AN - SCOPUS:35048824933
SN - 0302-9743
VL - 3043
SP - 608
EP - 616
JO - Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
JF - Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
ER -