Argumentation-Based Security Requirements Elicitation: The Next Round

被引:0
|
作者
Ionita, Dan [1 ]
Bullee, Jan-Willem [1 ]
Wieringa, Roel J. [1 ]
机构
[1] Univ Twente, Serv Cybersecur & Safety Res Grp, NL-7500 AE Enschede, Netherlands
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Information Security Risk Assessment can be viewed as part of requirements engineering because it is used to translate security goals into security requirements, where security requirements are the desired system properties that mitigate threats to security goals. To improve the defensibility of these mitigations, several researchers have attempted to base risk assessment on argumentation structures. However, none of these approaches have so far been scalable or usable in real-world risk assessments. In this paper, we present the results from our search for a scalable argumentation-based information security RA method. We start from previous work on both formal argumentation frameworks and informal argument structuring and try to find a promising middle ground. An initial prototype using spreadsheets is validated and iteratively improved via several Case Studies. Challenges such as scalability, quantify-ability, ease of use, and relation to existing work in parallel fields are discussed. Finally, we explore the scope and applicability of our approach with regard to various classes of Information Systems while also drawing more general conclusions on the role of argumentation in security.
引用
收藏
页码:7 / 12
页数:6
相关论文
共 50 条
  • [1] Argumentation-Based Security Requirements Analysis: BitMessage Case Study
    Kovacs, Andor
    Karakatsanis, Ioannis
    Svetinovic, Davor
    [J]. 2014 IEEE INTERNATIONAL CONFERENCE (ITHINGS) - 2014 IEEE INTERNATIONAL CONFERENCE ON GREEN COMPUTING AND COMMUNICATIONS (GREENCOM) - 2014 IEEE INTERNATIONAL CONFERENCE ON CYBER-PHYSICAL-SOCIAL COMPUTING (CPS), 2014, : 408 - 414
  • [2] An Argumentation-based Support System for Requirements Reconciliation
    Mirbel, Isabelle
    Villata, Serena
    [J]. COMPUTATIONAL MODELS OF ARGUMENT, 2014, 266 : 467 - 468
  • [3] Argumentation-Based Legal Requirements Engineering The Role of Legal Interpretation in Requirements Acquisition
    Muthuri, Robert
    Boella, Guido
    Hulstijn, Joris
    Humphreys, Llio
    [J]. 2016 IEEE 24TH INTERNATIONAL REQUIREMENTS ENGINEERING CONFERENCE WORKSHOPS (REW), 2016, : 249 - 258
  • [4] Argumentation-based learning
    Fukumoto, Taro
    Sawamura, Hajime
    [J]. ARGUMENTATION IN MULTI-AGENT SYSTEMS, 2007, 4766 : 17 - +
  • [5] Argumentation-based negotiation
    Rahwan, I
    Ramchurn, SD
    Jennings, NR
    McBurney, P
    Parsons, S
    Sonenberg, L
    [J]. KNOWLEDGE ENGINEERING REVIEW, 2003, 18 (04): : 343 - 375
  • [6] Argumentation-Based Negotiation? Negotiation-Based Argumentation!
    Landes, Juergen
    Buettner, Ricardo
    [J]. E-COMMERCE AND WEB TECHNOLOGIES, EC-WEB 2012, 2012, 123 : 149 - 162
  • [7] A framework for argumentation-based negotiation
    Sierra, C
    Jennings, NR
    Noriega, P
    Parsons, S
    [J]. INTELLIGENT AGENTS IV: AGENT THEORIES, ARCHITECTURES, AND LANGUAGES, 1998, 1365 : 177 - 192
  • [8] Argumentation-Based Reasoning with Preferences
    Cyras, Kristijonas
    [J]. HIGHLIGHTS OF PRACTICAL APPLICATIONS OF SCALABLE MULTI-AGENT SYSTEMS, 2016, 616 : 199 - 210
  • [9] Argumentation-based ontology engineering
    Tempich, Christoph
    Studer, Rudi
    Simperl, Elena
    Luczak, Markus
    Pinto, H. Sofia
    [J]. IEEE INTELLIGENT SYSTEMS, 2007, 22 (06) : 52 - 59
  • [10] Argumentation-based Ranking Logics
    Amgoud, Leila
    Ben-Naim, Jonathan
    [J]. PROCEEDINGS OF THE 2015 INTERNATIONAL CONFERENCE ON AUTONOMOUS AGENTS & MULTIAGENT SYSTEMS (AAMAS'15), 2015, : 1511 - 1519