A domain-specific language for the specification of UCON policies

被引:0
|
作者
Reina Quintero, Antonia M. [1 ]
Martinez Perez, Salvador [2 ]
Jesus Varela-Vaca, Angel [1 ]
Gomez Lopez, Maria Teresa [1 ]
Cabot, Jordi [3 ]
机构
[1] Univ Seville, Dept Lenguajes & Sistemas Informat, Seville, Spain
[2] IMT Atlantique, Lab STICC, Brest, France
[3] ICREA UOC, Barcelona, Catalunya, Spain
关键词
Cybersecurity; Access control; Model-driven engineering; UCON; DSL; ACCESS-CONTROL; SECURITY; UML;
D O I
10.1016/j.jisa.2021.103006
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Security policies constrain the behavior of all users of an information system. In any non-trivial system, these security policies go beyond simple access control rules and must cover more complex and dynamic scenarios while providing, at the same time, a fine-grained level decision-making ability. The Usage Control model (UCON) was created for this purpose but so far integration of UCON in mainstream software engineering processes has been very limited, hampering its usefulness and popularity among the software and information systems communities. In this sense, this paper proposes a Domain-Specific Language to facilitate the modeling of UCON policies and their integration in (model-based) development processes. Together with the language, an exploratory approach for policy evaluation and enforcement of the modeled policies via model transformations has been introduced. These contributions have been defined on top of the Eclipse Modeling Framework, the de-facto standard MDE (Model-Driven Engineering) framework making them freely available and ready-touse for any software designer interested in using UCON for the definition of security policies in their new development projects.
引用
收藏
页数:14
相关论文
共 50 条
  • [1] Specification and Refinement of Domain-Specific ECA Policies
    Romeikat, Raphael
    Bauer, Bernhard
    [J]. ADVANCED INFORMATION SYSTEMS ENGINEERING WORKSHOPS, 2011, 83 : 197 - 206
  • [2] RSL-IL4Privacy: a domain-specific language for the rigorous specification of privacy policies
    João Caramujo
    Alberto Rodrigues da Silva
    Shaghayegh Monfared
    André Ribeiro
    Pável Calado
    Travis Breaux
    [J]. Requirements Engineering, 2019, 24 : 1 - 26
  • [3] RSL-IL4Privacy: a domain-specific language for the rigorous specification of privacy policies
    Caramujo, Joao
    da Silva, Alberto Rodrigues
    Monfared, Shaghayegh
    Ribeiro, Andre
    Calado, Pavel
    Breaux, Travis
    [J]. REQUIREMENTS ENGINEERING, 2019, 24 (01) : 1 - 26
  • [4] HAPI: A domain-specific language for the declaration of access policies
    Ramos, Vinicius Juliao
    Holmquist, Alexander
    Pereira, Fernando Magno Quintao
    [J]. JOURNAL OF COMPUTER LANGUAGES, 2022, 72
  • [5] Enforcing Exception Handling Policies with a Domain-Specific Language
    Barbosa, Eiji Adachi
    Garcia, Alessandro
    Robillard, Martin P.
    Jakobus, Benjamin
    [J]. IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2016, 42 (06) : 559 - 584
  • [6] Hapi: A Domain-Specific Language for the Declaration of Access Policies
    Juliao, Vinicius
    Holmquist, Alexander
    Correa Junior, Flavio Lucio
    Oliveira Santos, Celso Junio S.
    Quintao Pereira, Fernando M.
    [J]. 25TH BRAZILIAN SYMPOSIUM ON PROGRAMMING LANGUAGES, SBLP 2021, 2021, : 9 - 16
  • [7] A Domain-Specific Language for the Specification of Gesture-based Applications
    Viana, Daniel Leite
    de Medeiros Santos, Andre Luis
    [J]. PROCEEDINGS OF THE 21ST BRAZILIAN SYMPOSIUM ON PROGRAMMING LANGUAGES (SBLP 2017), 2017,
  • [8] A Domain-Specific Modeling Language for Specification of Clinical Scores in Mobile Health
    de Aguiar Barbosa, Allan Fabio
    da Silva e Silva, Francisco Jose
    Coutinho, Luciano Reis
    dos Santos, Davi Viana
    Teles, Ariel Soares
    [J]. PROCEEDINGS OF THE 14TH INTERNATIONAL CONFERENCE ON EVALUATION OF NOVEL APPROACHES TO SOFTWARE ENGINEERING (ENASE), 2019, : 104 - 113
  • [9] A Domain-Specific Language for ETL Patterns Specification in Data Warehousing Systems
    Oliveira, Bruno
    Belo, Orlando
    [J]. PROGRESS IN ARTIFICIAL INTELLIGENCE-BK, 2015, 9273 : 597 - 602
  • [10] Certifying domain-specific policies
    Lowry, M
    Pressburger, T
    Rosu, G
    [J]. 16TH ANNUAL INTERNATIONAL CONFERENCE ON AUTOMATED SOFTWARE ENGINEERING (ASE 2001), PROCEEDINGS, 2001, : 81 - 90