摘要

Through the analysis and research on existing trusted software evaluation technology, an evidence-driven framework for trustworthiness evaluation of software based on rules is put forward, rules are used as expression method of trustworthiness evaluation logic, and evidence is used to drive the operation of trustworthiness evaluation process, trustworthiness evidence collection and processing logic as well as mapping method of trustworthiness levels have been encapsulated in rules, and the selection, instantiation, collection, format definition and measurement of trustworthiness evidence are carried out under the guidance of the rules, and the mapping of trustworthiness levels and the analysis of trustworthiness bottleneck are done based on the measured evidence instances, this framework has provided an application implementation scheme for software trustworthiness evaluation.

全文