Model driven security framework for software design and verification

被引:6
|
作者
Deveci, Engin [1 ]
Caglayan, Mehmet U. [1 ]
机构
[1] Bogazici Univ, Dept Comp Engn, Istanbul, Turkey
关键词
security; design tools and techniques; requirements/specifications; software engineering process; software/program verification; INFORMATION-SYSTEMS; UML;
D O I
10.1002/sec.1200
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Information system security is receiving increasing attention every day because a security problem can cause serious financial loss or even loss of lives. Some of these security problems occur as a result of poor design practices, where important security functionality is not designed properly and is directly implemented later in the development cycle in an unmethodical way. Researchers have put a great deal of effort into defining processes and tools to design and develop more secure information systems. However, verification of the designed and developed security functionality is of utmost importance. In some cases, designs and codes also need to be formally or semi-formally verified and certified by authorities. The Common Criteria is one of the widely used universal frameworks for evaluating the security functionality of information systems. In this paper, we propose a new framework, model driven security framework, for the analysis, design, and evaluation of security properties of information systems. Our aim is to support information system developers and evaluation authorities who implement the higher-level Common Criteria (levels 6 and 7) security assurance process using formal methods based on Unified Modelling Language, Object Constraint Language, Promela, and Spin. Copyright (c) 2015John Wiley & Sons, Ltd.
引用
收藏
页码:2768 / 2792
页数:25
相关论文
共 50 条
  • [31] A generative style-driven framework for software architecture design
    Kong, J
    Zhang, K
    Dong, J
    Song, GL
    [J]. 29TH ANNUAL IEEE/NASA SOFTWARE ENGINEERING WORKSHOP, PROCEEDINGS, 2005, : 173 - 182
  • [32] Applied Threat Driven Security Verification
    Dhillon, Danny
    Mishra, Vishal
    [J]. 2018 IEEE CYBERSECURITY DEVELOPMENT CONFERENCE (SECDEV 2018), 2018, : 135 - 135
  • [33] The Research and Design of the Intelligent Security Defendable Software's Cooperative Framework
    Wang, Jin-Dong
    Cao, Wei-Wei
    Wang, Kun
    Zhang, Heng-Wei
    [J]. ISBIM: 2008 INTERNATIONAL SEMINAR ON BUSINESS AND INFORMATION MANAGEMENT, VOL 2, 2009, : 273 - 276
  • [34] Design and analysis of a robust security layer for software defined network framework
    Alhaj, Ali Nadim
    Patel, Narottam Das
    Singh, Ajeet
    Bondugula, Rohit Kumar
    Dar, Mohsin Furkh
    Ahamed, Jameel
    [J]. INTERNATIONAL JOURNAL OF SENSOR NETWORKS, 2024, 46 (01)
  • [35] Towards a Tracing Framework for Model-Driven Software Systems
    Hojaji, Fazilat
    Zamani, Bahman
    Hamou-Lhadj, Abdelwahab
    [J]. 2016 6TH INTERNATIONAL CONFERENCE ON COMPUTER AND KNOWLEDGE ENGINEERING (ICCKE), 2016, : 298 - 303
  • [36] A model-driven traceability framework for software product lines
    Nicolas Anquetil
    Uirá Kulesza
    Ralf Mitschke
    Ana Moreira
    Jean-Claude Royer
    Andreas Rummler
    André Sousa
    [J]. Software & Systems Modeling, 2010, 9 : 427 - 451
  • [37] Model-Driven Software Measurement Framework: a case study
    Mora, Beatriz
    Garcia, Felix
    Ruiz, Francisco
    Piattini, Mario
    [J]. 2009 NINTH INTERNATIONAL CONFERENCE ON QUALITY SOFTWARE (QSIC 2009), 2009, : 239 - +
  • [38] OpenPMF: A model-driven security framework for distributed systems
    Lang, U
    Schreiner, R
    [J]. ISSE 2004 - SECURING ELECTRONIC BUSINESS PROCESSES, 2004, : 138 - 147
  • [39] A model-driven traceability framework for software product lines
    Anquetil, Nicolas
    Kulesza, Uira
    Mitschke, Ralf
    Moreira, Ana
    Royer, Jean-Claude
    Rummler, Andreas
    Sousa, Andre
    [J]. SOFTWARE AND SYSTEMS MODELING, 2010, 9 (04): : 427 - 451
  • [40] A Method of Software System Security Verification and Evaluation Based on Extension of AADL Model
    Wang Bohan
    Ke Wenjun
    Zhang Jianwei
    Gao Xinrui
    Chen Jing
    Wang Kunlong
    Yang Yuting
    Da Yifei
    [J]. 2018 EIGHTH INTERNATIONAL CONFERENCE ON INSTRUMENTATION AND MEASUREMENT, COMPUTER, COMMUNICATION AND CONTROL (IMCCC 2018), 2018, : 1726 - 1731