SoK:通用标准产品评估中的失效模式——分类与可评估性设计指南
SoK: Failure Modes in Common Criteria Product Evaluation - A Taxonomy and Design-for-Evaluability Guidance
AI总结:
本文系统梳理通用标准产品评估中的失效模式,构建生命周期分类,推导可评估性设计框架,明确云等新兴系统的相关开放问题。
AI中文摘要:
通用标准(CC;ISO/IEC 15408)是评估IT产品安全性的主要国际框架,其证书是政府、国防及受监管行业采购的准入门槛。然而评估常陷入停滞、失败,或出具的证书在实际部署中无法保障安全。现有研究从两方面切入:一是对激励错位与“安全表演”的经济批判,二是近期量化已认证产品漏洞的数据驱动研究。相较而言,从评估者操作视角系统梳理问题的研究较少——即针对通用标准工作单元本身、跨供应商反复出现的失效。本文提出通用标准产品评估失效模式的知识系统化(SoK)研究,结合标准、通用评估方法(ISO/IEC 18045)、公开的NIAP保护轮廓及已发布的安全目标与认证报告,将反复出现的失效组织为覆盖安全目标范围界定、保护轮廓符合性、保障证据、加密要求、功能测试、漏洞分析、操作指南及认证后配置漂移的生命周期分类。我们分析其根本原因,推导产品团队可在评估前应用的可评估性设计框架,并指出云、持续交付及AI驱动系统的开放问题。
英文摘要:
The Common Criteria (CC; ISO/IEC 15408) is the principal international framework for evaluating the security of IT products, and its certificates gate procurement across government, defense, and regulated industry. Yet evaluations routinely stall, fail, or yield certificates whose assurances do not survive real-world deployment. Prior work has approached this from two directions: economic critiques of misaligned incentives and "security theatre"; and recent data-driven studies that quantify vulnerabilities in already-certified products. Comparatively little systematizes the problem from the evaluator's operational vantage - recurring, cross-vendor failures against the Common Criteria work units themselves. This paper presents a systematization of knowledge (SoK) of failure modes in Common Criteria product evaluation. Drawing on the standard, the Common Evaluation Methodology (ISO/IEC 18045), public NIAP Protection Profiles, and published Security Targets and Certification Reports, we organize recurring failures into a lifecycle taxonomy spanning Security Target scoping, Protection Profile conformance, assurance evidence, cryptographic requirements, functional testing, vulnerability analysis, operational guidance, and post-certification configuration drift. We analyze their root causes, derive a design-for-evaluability framework that product teams can apply before evaluation begins, and identify open problems for cloud, continuous-delivery, and AI-enabled systems.