Building Secure Applications using Pattern-Based Design Fragments

被引:1
|
作者
Rimba, Paul [1 ,2 ]
Zhu, Liming [1 ,2 ]
Xu, Xiwei [1 ]
Sun, Daniel [1 ,2 ]
机构
[1] NICTA, Sydney, NSW, Australia
[2] Univ New South Wales, Sch Comp Sci & Engn, Sydney, NSW, Australia
关键词
Security; Composition; Verification; Operations;
D O I
10.1109/SRDSW.2015.12
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Developing and operating a complex secure application with high assurance is difficult and requires experts. Security patterns and best practices have been proposed to assist architects in designing secure applications. However, these are usually written independently of the underlying platforms and operating environment. This leads to a gap between patterns and the platforms, and does not directly support the design-level analysis and verification of systems to be built on those platforms. We propose an approach to incrementally build an application design using design fragments, which are specializations of patterns for target platforms. Design fragments can be composed and reused during design, and directly support design-level security analyses and operation level concerns. We apply this approach in a case study of the design and analysis of a smart electricity meter. We show how the approach can be used to iteratively address threats.
引用
收藏
页码:19 / 24
页数:6
相关论文
共 50 条
  • [41] On the Design of Pattern-Based Block Motion Estimation Algorithms
    Tsai, Jang-Jer
    Hang, Hsueh-Ming
    IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS FOR VIDEO TECHNOLOGY, 2010, 20 (01) : 136 - 143
  • [42] A Transformational Approach for Pattern-based Design of User Interfaces
    Pribeanu, Costin
    Vanderdonckt, Jean
    FOURTH INTERNATIONAL CONFERENCE ON AUTONOMIC AND AUTONOMOUS SYSTEMS (ICAS 2008), 2008, : 47 - +
  • [43] Pattern-Based Model Transformation Using QVT
    Park, Sunuk
    Kim, Dae-Kyoo
    Park, Sooyong
    2012 19TH ASIA-PACIFIC SOFTWARE ENGINEERING CONFERENCE (APSEC), VOL 1, 2012, : 472 - 481
  • [44] Design pattern-based model transformation supported by QVT
    Kim, Dae-Kyoo
    Lu, Lunjin
    Lee, Byunghun
    JOURNAL OF SYSTEMS AND SOFTWARE, 2017, 125 : 289 - 308
  • [45] Formalising Middleware Systems: A Design Pattern-based Approach
    Rosa, Nelson Souto
    2013 IEEE 37TH ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE (COMPSAC), 2013, : 658 - 667
  • [46] Pattern-based refinement schemas for design knowledge transfer
    Khriss, I
    Keller, RK
    Hamid, IA
    KNOWLEDGE-BASED SYSTEMS, 2000, 13 (06) : 403 - 415
  • [47] Business model driven design of service architectures for Enterprise Applications Integration: A pattern-based approach
    Gacitua-Decar, Veronica
    Pahl, Claus
    DCSOFT 2008: PROCEEDINGS OF THE DOCTORAL CONSORTIUM ON SOFTWARE AND DATA TECHNOLOGIES, 2008, : 53 - 64
  • [48] Pattern-based design and validation of business process compliance
    Namiri, Kioumars
    Stojanovic, Nenad
    ON THE MOVE TO MEANINGFUL INTERNET SYSTEMS 2007: COOPLS, DOA, ODBASE, GADA, AND IS, PT 1, PROCEEDINGS, 2007, 4803 : 59 - +
  • [49] Pattern-based Design Research in Enterprise Architecture Management
    Buckl, Sabine
    Matthes, Florian
    Schneider, Alexander W.
    Schweda, Christian M.
    ADVANCED INFORMATION SYSTEMS ENGINEERING WORKSHOPS (CAISE), 2013, 148 : 30 - 42
  • [50] Pattern-based image retrieval using GLCM
    Srivastava, Divya
    Rajitha, B.
    Agarwal, Suneeta
    Singh, Shruti
    NEURAL COMPUTING & APPLICATIONS, 2020, 32 (15): : 10819 - 10832