Advances in Model-Driven Security

被引:18
|
作者
Lucio, Levi [1 ]
Zhang, Qin [2 ]
Nguyen, Phu H. [2 ]
Amrani, Moussa [2 ]
Klein, Jacques [2 ]
Vangheluwe, Hans [1 ,3 ]
Le Traon, Yves [2 ]
机构
[1] McGill Univ, Modeling Simulat & Design Lab, Montreal, PQ, Canada
[2] Univ Luxembourg, Ctr Secur Reliabil & Trust, Luxembourg, Luxembourg
[3] Univ Antwerp, Dept Math & Comp Sci, B-2020 Antwerp, Belgium
来源
关键词
SYSTEMS; FRAMEWORK; DESIGN; VERIFICATION; ARCHITECTURE; GENERATION; POLICIES; SMART;
D O I
10.1016/B978-0-12-800162-2.00003-8
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Sound methodologies for constructing security-critical systems are extremely important in order to confront the increasingly varied security threats. As a response to this need, Model-Driven Security has emerged in the early 2000s as a specialized Model-Driven Engineering approach for supporting the development of security-critical systems. In this chapter we summarize the most important developments of Model-Driven Security during the past decade. In order to do so we start by building a taxonomy of the most important concepts of this domain. We then use our taxonomy to describe and evaluate a set of representative and influential Model-Driven Security approaches in the literature. In our development of this topic we concentrate on the concepts shared by Model-Driven Engineering and Model-Driven Security. This allows us to identify and debate the advantages, disadvantages, and open issues when applying Model-Driven Engineering to the Information Security domain. This chapter provides a broad view of Model-Driven Security and is intended as an introduction to Model-Driven Security for students, researchers, and practitioners.
引用
收藏
页码:103 / 152
页数:50
相关论文
共 50 条
  • [1] A Systematic Review of Model-Driven Security
    Nguyen, Phu H.
    Klein, Jacques
    Le Traon, Yves
    Kramer, Max E.
    [J]. 2013 20TH ASIA-PACIFIC SOFTWARE ENGINEERING CONFERENCE (APSEC 2013), VOL 1, 2013, : 432 - 441
  • [2] MODEL-DRIVEN SECURITY FOR TRUSTED SYSTEMS
    Alam, Masoom
    Khan, Shahbaz
    Alam, Quratulain
    Ali, Tamleek
    Anwar, Sajid
    Hayat, Amir
    Jaffar, Arfan
    Ali, Muhammad
    Adnan, Awais
    [J]. INTERNATIONAL JOURNAL OF INNOVATIVE COMPUTING INFORMATION AND CONTROL, 2012, 8 (02): : 1221 - 1235
  • [3] Model-driven architecture based security analysis
    Mili, Saoussen
    Nguyen, Nga
    Chelouah, Rachid
    [J]. SYSTEMS ENGINEERING, 2021, 24 (05) : 307 - 321
  • [4] MODEL-DRIVEN ENGINEERING OF FUNCTIONAL SECURITY POLICIES
    Jiague, Michel Embe
    Frappier, Marc
    Gervais, Frederic
    Konopacki, Pierre
    Laleau, Regine
    Milhau, Jeremy
    St-Denis, Richard
    [J]. ICEIS 2010: PROCEEDINGS OF THE 12TH INTERNATIONAL CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS, VOL 3: INFORMATION SYSTEMS ANALYSIS AND SPECIFICATION, 2010, : 374 - 379
  • [5] Model-driven security in practice: An industrial experience
    Clavel, Manuel
    da Silva, Viviane
    Braga, Christiano
    Egea, Marina
    [J]. MODEL DRIVEN ARCHITECTURE - FOUNDATIONS AND APPLICATIONS, PROCEEDINGS, 2008, 5095 : 326 - +
  • [6] ModelSec: A Generative Architecture for Model-Driven Security
    Sanchez, Oscar
    Molina, Fernando
    Garcia-Molina, Jesus
    Toval, Ambrosio
    [J]. JOURNAL OF UNIVERSAL COMPUTER SCIENCE, 2009, 15 (15) : 2957 - 2980
  • [7] A Model-Driven approach to Information Security Compliance
    Correia, Anacleto
    Goncalves, Antonio
    Filomena Teodoro, M.
    [J]. APPLIED MATHEMATICS AND COMPUTER SCIENCE, 2017, 1836
  • [8] Towards a Model-driven based Security Framework
    Abdallah, Rouwaida
    Yakymets, Nataliya
    Lanusse, Agnes
    [J]. MODELSWARD 2015 PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON MODEL-DRIVEN ENGINEERING AND SOFTWARE DEVELOPMENT, 2015, : 639 - 645
  • [9] Model-driven security based on a Web services security architecture
    Nakamura, Y
    Tatsubori, M
    Imamura, T
    Ono, K
    [J]. 2005 IEEE INTERNATIONAL CONFERENCE ON SERVICES COMPUTING, VOL 1, PROCEEDINGS, 2005, : 7 - 15
  • [10] Model-driven security management of embedded service systems
    Illner, S
    Pohl, A
    Krumm, H
    [J]. IECON 2005: THIRTY-FIRST ANNUAL CONFERENCE OF THE IEEE INDUSTRIAL ELECTRONICS SOCIETY, VOLS 1-3, 2005, : 2655 - 2660