Model-Driven Development of Information Flow-Secure Systems with IFlow

被引:8
|
作者
Katkalov, Kuzman [1 ]
Stenzel, Kurt [1 ]
Borek, Marian [1 ]
Reif, Wolfgang [1 ]
机构
[1] Univ Augsburg, Inst Software & Syst Engn, D-86135 Augsburg, Germany
关键词
model-driven software development; information flow control; mobile apps; web services;
D O I
10.1109/SocialCom.2013.14
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In our increasingly interconnected world, privacy can seem like an unattainable goal. We are surrounded by countless devices and web services that acquire and collect our personal data as we interact with them. In many cases, the confidentiality of such data is not guaranteed and is frequently (if not always intentionally) violated. Smartphone apps and Internet web services in particular are known to often leak their users' confidential data to other users or (affiliated) third parties. We present a novel model-driven approach called IFlow that allows the development of distributed applications consisting of mobile apps and web services with secure information flow. In IFlow, a UML model of an information flow-sensitive application is used to automatically generate deployable app and web service code as well as a formal model. By employing automatic, language-based information flow control as well as interactive verification, IFlow enables the developer to give verifiable guarantees to the user about how his private data is being treated by the application.
引用
收藏
页码:51 / 56
页数:6
相关论文
共 50 条
  • [1] Model-Driven Development for secure information systems
    Fernandez-Medina, Eduardo
    Jurjens, Jan
    Trujillo, Juan
    Jajodia, Sushil
    [J]. INFORMATION AND SOFTWARE TECHNOLOGY, 2009, 51 (05) : 809 - 814
  • [2] An extensive systematic review on the Model-Driven Development of secure systems
    Nguyen, Phu H.
    Kramer, Max
    Klein, Jacques
    Le Traon, Yves
    [J]. INFORMATION AND SOFTWARE TECHNOLOGY, 2015, 68 : 62 - 81
  • [3] Model-driven Secure Development Lifecycle
    Ma, Zhendong
    Wagner, Christian
    Bonitz, Arndt
    Bleier, Thomas
    Woitsch, Robert
    Nichterl, Markus
    [J]. INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2012, 6 (02): : 443 - 448
  • [4] A MODEL-DRIVEN SYSTEMS DEVELOPMENT METHOD FOR MANAGEMENT INFORMATION SYSTEMS
    Matsumoto, Keinosuke
    Mizuno, Tomoki
    Mori, Naoki
    [J]. KEOD 2010: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON KNOWLEDGE ENGINEERING AND ONTOLOGY DEVELOPMENT, 2010, : 10 - 16
  • [5] A model-driven development method for Management Information Systems
    Mizuno, Tomoki
    Matsumoto, Keinosuke
    Mori, Naoki
    [J]. ELECTRONICS AND COMMUNICATIONS IN JAPAN, 2013, 96 (02) : 16 - 24
  • [6] Model-Driven Traceability in Healthcare Information Systems Development
    Walderhaug, Stale
    Hartvigsen, Gunnar
    Stav, Erlend
    [J]. MEDINFO 2010, PTS I AND II, 2010, 160 : 242 - 246
  • [7] Model-Driven Development of Secure Service Applications
    Borek, Marian
    Moebius, Nina
    Stenzel, Kurt
    Reif, Wolfgang
    [J]. PROCEEDINGS OF THE 2012 IEEE 35TH SOFTWARE ENGINEERING WORKSHOP (SEW 2012), 2012, : 62 - 71
  • [8] Model-driven secure system development framework
    Kaugers, Viesturs
    Sukovskis, Uldis
    [J]. BALTIC JOURNAL OF MODERN COMPUTING, 2010, 757 : 43 - 52
  • [9] Model-driven systems development
    Balmelli, L.
    Brown, D.
    Cantor, M.
    Mott, M.
    [J]. IBM SYSTEMS JOURNAL, 2006, 45 (03) : 569 - 585
  • [10] SERVICE ORIENTED AND MODEL-DRIVEN DEVELOPMENT METHODS OF INFORMATION SYSTEMS
    Lemmik, R.
    Karjust, K.
    Koov, K.
    [J]. PROCEEDINGS OF THE 7TH INTERNATIONAL CONFERENCE OF DAAAM BALTIC INDUSTRIAL ENGINEERING, VOLS 1 AND 2, 2010, : 404 - +