Building Secure Applications using Pattern-Based Design Fragments

被引:1
|
作者
Rimba, Paul [1 ,2 ]
Zhu, Liming [1 ,2 ]
Xu, Xiwei [1 ]
Sun, Daniel [1 ,2 ]
机构
[1] NICTA, Sydney, NSW, Australia
[2] Univ New South Wales, Sch Comp Sci & Engn, Sydney, NSW, Australia
关键词
Security; Composition; Verification; Operations;
D O I
10.1109/SRDSW.2015.12
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Developing and operating a complex secure application with high assurance is difficult and requires experts. Security patterns and best practices have been proposed to assist architects in designing secure applications. However, these are usually written independently of the underlying platforms and operating environment. This leads to a gap between patterns and the platforms, and does not directly support the design-level analysis and verification of systems to be built on those platforms. We propose an approach to incrementally build an application design using design fragments, which are specializations of patterns for target platforms. Design fragments can be composed and reused during design, and directly support design-level security analyses and operation level concerns. We apply this approach in a case study of the design and analysis of a smart electricity meter. We show how the approach can be used to iteratively address threats.
引用
收藏
页码:19 / 24
页数:6
相关论文
共 50 条
  • [31] A pattern-based methodology for multimodal interaction design
    Ratzka, Andreas
    Wolff, Christian
    TEXT, SPEECH AND DIALOGUE, PROCEEDINGS, 2006, 4188 : 677 - 686
  • [32] Pattern-Based Security Requirements Derivation from Secure Tropos Models
    Rrenja, Atilio
    Matulevicius, Raimundas
    PRACTICE OF ENTERPRISE MODELING, POEM 2015, 2015, 235 : 59 - 74
  • [33] Towards a Pattern-Based Security Methodology to Build Secure Information Systems
    Ortiz, Roberto
    Moral-Rubio, Santiago
    Garzas, Javier
    Fernandez-Medina, Eduardo
    WOSIS 2011: SECURITY IN INFORMATION SYSTEMS, 2011, : 59 - +
  • [34] Evaluation of the Pattern-based method for Secure Development (PbSD): A controlled experiment
    Abramov, Jenny
    Sturm, Arnon
    Shoval, Peretz
    INFORMATION AND SOFTWARE TECHNOLOGY, 2012, 54 (09) : 1029 - 1043
  • [35] Pattern-Based Methodology for Building the Ontologies of Scientific Subject Domains
    Zagorulko, Yury
    Zagorulko, Galina
    Borovikova, Olesya
    NEW TRENDS IN INTELLIGENT SOFTWARE METHODOLOGIES, TOOLS AND TECHNIQUES (SOMET_18), 2018, 303 : 529 - 542
  • [36] Paraprox: Pattern-Based Approximation for Data Parallel Applications
    Samadi, Mehrzad
    Jamshidi, Davoud Anoushe
    Lee, Janghaeng
    Mahlke, Scott
    ACM SIGPLAN NOTICES, 2014, 49 (04) : 35 - 50
  • [37] Pattern-based architecture for building mobile robotics remote laboratories
    Khamis, A
    Rivero, DM
    Rodríguez, F
    Salichs, M
    2003 IEEE INTERNATIONAL CONFERENCE ON ROBOTICS AND AUTOMATION, VOLS 1-3, PROCEEDINGS, 2003, : 3284 - 3289
  • [38] A pattern-based automated approach to building energy model calibration
    Sun, Kaiyu
    Hong, Tianzhen
    Taylor-Lange, Sarah C.
    Piette, Mary Ann
    APPLIED ENERGY, 2016, 165 : 214 - 224
  • [39] Pattern-Based Resolution of Integration Mismatches in Enterprise Applications
    Soldani, Jacopo
    Paoletti, Riccardo
    Brogi, Antonio
    SERVICE-ORIENTED AND CLOUD COMPUTING, 2022, 13226 : 93 - 108
  • [40] A Generic Pattern-based Design for Distributed Collaborative Editors
    Cherif, Asma
    TEM JOURNAL-TECHNOLOGY EDUCATION MANAGEMENT INFORMATICS, 2020, 9 (02): : 633 - 640