Model driven security framework for software design and verification

被引:6
|
作者
Deveci, Engin [1 ]
Caglayan, Mehmet U. [1 ]
机构
[1] Bogazici Univ, Dept Comp Engn, Istanbul, Turkey
关键词
security; design tools and techniques; requirements/specifications; software engineering process; software/program verification; INFORMATION-SYSTEMS; UML;
D O I
10.1002/sec.1200
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Information system security is receiving increasing attention every day because a security problem can cause serious financial loss or even loss of lives. Some of these security problems occur as a result of poor design practices, where important security functionality is not designed properly and is directly implemented later in the development cycle in an unmethodical way. Researchers have put a great deal of effort into defining processes and tools to design and develop more secure information systems. However, verification of the designed and developed security functionality is of utmost importance. In some cases, designs and codes also need to be formally or semi-formally verified and certified by authorities. The Common Criteria is one of the widely used universal frameworks for evaluating the security functionality of information systems. In this paper, we propose a new framework, model driven security framework, for the analysis, design, and evaluation of security properties of information systems. Our aim is to support information system developers and evaluation authorities who implement the higher-level Common Criteria (levels 6 and 7) security assurance process using formal methods based on Unified Modelling Language, Object Constraint Language, Promela, and Spin. Copyright (c) 2015John Wiley & Sons, Ltd.
引用
收藏
页码:2768 / 2792
页数:25
相关论文
共 50 条
  • [1] A Framework for Security Driven Software Evolution
    Guan, Hui
    Yang, Hongji
    Wang, Xuan
    [J]. PROCEEDINGS OF THE 2014 20TH INTERNATIONAL CONFERENCE ON AUTOMATION AND COMPUTING (ICAC'14), 2014, : 194 - +
  • [2] Model-driven software verification
    Holzmann, GJ
    Joshi, R
    [J]. MODEL CHECKING SOFTWARE, 2004, 2989 : 76 - 91
  • [3] A framework for the design and verification of software measurement methods
    Habra, Naji
    Abran, Alain
    Lopez, Miguel
    Sellami, Asma
    [J]. JOURNAL OF SYSTEMS AND SOFTWARE, 2008, 81 (05) : 633 - 648
  • [4] A DATA DRIVEN ORCHESTRATION FRAMEWORK IN SOFTWARE DEFINED SECURITY
    Wang, Weijia
    Qiu, Xiaofeng
    Sun, Li
    Zhao, Rui
    [J]. PROCEEDINGS OF 2016 5TH IEEE INTERNATIONAL CONFERENCE ON NETWORK INFRASTRUCTURE AND DIGITAL CONTENT (IEEE IC-NIDC 2016), 2016, : 34 - 39
  • [5] Software Design and Software Product Verification From Security Point of View
    Ozkohen, Albert
    [J]. INNOVATION AND SUSTAINABLE COMPETITIVE ADVANTAGE: FROM REGIONAL DEVELOPMENT TO WORLD ECONOMIES, VOLS 1-5, 2012, : 2896 - 2905
  • [6] Design of Software Security Verification with Formal Method Tools
    Jang, Seung-Ju
    Ryoo, Jungwoo
    Lee, ChangYeol
    [J]. INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2006, 6 (9B): : 163 - 167
  • [7] A model-driven framework for design and verification of embedded systems through SystemVerilog
    Anwar, Muhammad Waseem
    Rashid, Muhammad
    Azam, Farooque
    Kashif, Muhammad
    Butt, Wasi Haider
    [J]. DESIGN AUTOMATION FOR EMBEDDED SYSTEMS, 2019, 23 (3-4) : 179 - 223
  • [8] A model-driven framework for design and verification of embedded systems through SystemVerilog
    Muhammad Waseem Anwar
    Muhammad Rashid
    Farooque Azam
    Muhammad Kashif
    Wasi Haider Butt
    [J]. Design Automation for Embedded Systems, 2019, 23 : 179 - 223
  • [9] Design units - A framework for design driven software development
    Kim, J
    Carlson, CR
    [J]. OOIS 2000: 6TH INTERNATIONAL CONFERENCE ON OBJECT ORIENTED INFORMATION SYSTEMS, PROCEEDINGS, 2001, : 54 - 64
  • [10] MDD: A Unified Model-Driven Design Framework for Embedded Control Software
    Su, Zhuo
    Wang, Dongyan
    Yang, Yixiao
    Yu, Zehong
    Chang, Wanli
    Li, Wen
    Cui, Aiguo
    Jiang, Yu
    Sun, Jiaguang
    [J]. IEEE TRANSACTIONS ON COMPUTER-AIDED DESIGN OF INTEGRATED CIRCUITS AND SYSTEMS, 2022, 41 (10) : 3252 - 3265