Towards security modeling of e-voting systems

被引:0
|
作者
De Faveri, Cristiano [1 ]
Moreira, Ana [1 ]
Araujo, Joao [1 ]
Amaral, Vasco [1 ]
机构
[1] Univ Nova Lisboa, Fac Sci & Technol, Dept Comp Sci, NOVA LINCS, Lisbon, Portugal
关键词
REQUIREMENTS;
D O I
10.1109/REW.2016.37
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
As voting systems evolve from paper ballots to electronic voting (E-voting) applications, we have noticed significant efforts to develop real-world securer solutions. E-voting systems are security-critical systems that require early identification of security requirements and controls based on the analyses of potential vulnerabilities, threats, attacks, and associated risks. General purpose modeling languages and current tool support to model security concerns exist. However, they lack a comprehensive solution that includes tool support for verification of security goal completeness and risk analysis in specific domains. Also, communication between stakeholders in large-scale systems is difficult, specially because security is not the core skill of many requirements engineers. To overcome these challenges in the electronic voting domain, we developed EVSec, a domain-specific visual modeling language. EVSec is process-centric language and allows modelers expressing activities and social interactions, while identifying security concerns with associated risks. Comprehensive tool support provides security goals completeness and assists users on the identification of critical parts of the model with higher security risks. We used EVSec to model the Brazilian national election, demonstrating its adequacy.
引用
收藏
页码:145 / 154
页数:10
相关论文
共 50 条
  • [1] E-voting security
    Dill, DL
    Rubin, AD
    [J]. IEEE SECURITY & PRIVACY, 2004, 2 (01) : 22 - 23
  • [2] Security in e-voting
    Kuesters, Ralf
    Truderung, Tomasz
    [J]. IT-INFORMATION TECHNOLOGY, 2014, 56 (06): : 300 - 306
  • [3] Practical security analysis of E-Voting Systems
    Buldas, Ahto
    Maegi, Trimu
    [J]. ADVANCES IN INFORMATION AND COMPUTER SECURITY, PROCEEDINGS, 2007, 4752 : 320 - +
  • [4] The Security and the Credibility Challenges in e-Voting Systems
    Rana, Ahmed
    Zincir, Ibrahim
    Basarici, Samsun
    [J]. PROCEEDINGS OF THE 14TH EUROPEAN CONFERENCE ON CYBER WARFARE AND SECURITY (ECCWS-2015), 2015, : 229 - 232
  • [5] Developments in e-voting security
    Schultz, E
    [J]. COMPUTERS & SECURITY, 2004, 23 (04) : 273 - 274
  • [6] E-Voting Systems
    Kuesters, Ralf
    [J]. SOFTWARE SYSTEMS SAFETY, 2014, 36 : 135 - 164
  • [7] Towards Blockchain-Based E-Voting Systems
    Braghin, Chiara
    Cimato, Stelvio
    Cominesi, Simone Raimondi
    Damiani, Ernesto
    Mauri, Lara
    [J]. BUSINESS INFORMATION SYSTEMS WORKSHOPS, BIS 2019, 2019, 373 : 274 - 286
  • [8] An Integrated Application of Security Testing Methodologies to e-voting Systems
    Ramilli, Marco
    Prandini, Marco
    [J]. ELECTRONIC PARTICIPATION, 2010, 6229 : 225 - 236
  • [9] Building secure elections: E-voting, security, and systems theory
    Moynihan, DP
    [J]. PUBLIC ADMINISTRATION REVIEW, 2004, 64 (05) : 515 - 528
  • [10] Realities of E-voting Security INTRODUCTION
    Shamos, Michael
    Yasinsac, Alec
    [J]. IEEE SECURITY & PRIVACY, 2012, 10 (05) : 16 - 17