软件能力成熟度模型(Capability maturity model integration,CMMI)被众多企业重视及推广应用,这不仅体现一个软件开发单位的CMMI等级,而且可以帮助软件开发单位进行自我检验,不断优化单位的软件开发过程,提高软件质量,软件开发效率,提...软件能力成熟度模型(Capability maturity model integration,CMMI)被众多企业重视及推广应用,这不仅体现一个软件开发单位的CMMI等级,而且可以帮助软件开发单位进行自我检验,不断优化单位的软件开发过程,提高软件质量,软件开发效率,提升客户对产品的满意度。文章依据CMMI相关过程域对软件评审过程度量的支持框架,参照企业实际情况进行评审过程质量的度量分析,运用传统的过程度量方法以及统计技术对软件评审过程度量进行研究。展开更多
In this paper, we consider a cost-based extension of intrusion detection capability (CID). An objective metric motivated by information theory is presented and based on this formulation;a package for computing the int...In this paper, we consider a cost-based extension of intrusion detection capability (CID). An objective metric motivated by information theory is presented and based on this formulation;a package for computing the intrusion detection capability of intrusion detection system (IDS), given certain input parameters is developed using Java. In order to determine the expected cost at each IDS operating point, the decision tree method of analysis is employed, and plots of expected cost and intrusion detection capability against false positive rate were generated. The point of intersection between the maximum intrusion detection capability and the expected cost is selected as the optimal operating point. Considering an IDS in the context of its intrinsic ability to detect intrusions at the least expected cost, findings revealed that the optimal operating point is the most suitable for the given IDS. The cost-based extension is used to select optimal operating point, calculate expected cost, and compare two actual intrusion detectors. The proposed cost-based extension of intrusion detection capability will be very useful to information technology (IT), telecommunication firms, and financial institutions, for making proper decisions in evaluating the suitability of an IDS for a specific operational environment.展开更多
文摘软件能力成熟度模型(Capability maturity model integration,CMMI)被众多企业重视及推广应用,这不仅体现一个软件开发单位的CMMI等级,而且可以帮助软件开发单位进行自我检验,不断优化单位的软件开发过程,提高软件质量,软件开发效率,提升客户对产品的满意度。文章依据CMMI相关过程域对软件评审过程度量的支持框架,参照企业实际情况进行评审过程质量的度量分析,运用传统的过程度量方法以及统计技术对软件评审过程度量进行研究。
文摘In this paper, we consider a cost-based extension of intrusion detection capability (CID). An objective metric motivated by information theory is presented and based on this formulation;a package for computing the intrusion detection capability of intrusion detection system (IDS), given certain input parameters is developed using Java. In order to determine the expected cost at each IDS operating point, the decision tree method of analysis is employed, and plots of expected cost and intrusion detection capability against false positive rate were generated. The point of intersection between the maximum intrusion detection capability and the expected cost is selected as the optimal operating point. Considering an IDS in the context of its intrinsic ability to detect intrusions at the least expected cost, findings revealed that the optimal operating point is the most suitable for the given IDS. The cost-based extension is used to select optimal operating point, calculate expected cost, and compare two actual intrusion detectors. The proposed cost-based extension of intrusion detection capability will be very useful to information technology (IT), telecommunication firms, and financial institutions, for making proper decisions in evaluating the suitability of an IDS for a specific operational environment.