Argumentation-Based Security Requirements Analysis: BitMessage Case Study

被引:1
|
作者
Kovacs, Andor [1 ]
Karakatsanis, Ioannis [1 ]
Svetinovic, Davor [1 ]
机构
[1] Masdar Inst Sci & Technol, Elect Engn & Comp Sci, Abu Dhabi, U Arab Emirates
关键词
Security Requirements; Requirements engineering; Risk-based Argumentation;
D O I
10.1109/iThings.2014.74
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Developers have to ensure that their systems meet certain security requirements. Structured argumentation can be a powerful tool for developers to deal with system behavior, vulnerabilities, and threats. Haley's framework is based on construction of a context for the system, representing security requirements as constraints, and developing satisfaction arguments for the security requirements. Incomplete and uncertain information and limited resources force the developers to settle for good-enough security. Risk assessment in Security Argumentation (RISA) extends Haley's method with risk assessment. RISA uses publicly available catalogs of security expertise and most common attack patterns to support risk assessment. These catalogs provide valuable information to the assessment process and help the developers identify mitigations for security requirements satisfaction. RISA developers stated the most pressing issue of their future work is the validation of RISA. In previous studies, no validation of RISA framework has been done on a complex system. Hence, this work evaluates RISA framework by applying it to the security requirements analysis of the address generation module of the decentralized, peer-to-peer communication protocol BitMessage. In addition, based on this analysis, we suggest a new set of requirements to improve the security of the current BitMessage client version.
引用
收藏
页码:408 / 414
页数:7
相关论文
共 50 条
  • [1] Argumentation-Based Security Requirements Elicitation: The Next Round
    Ionita, Dan
    Bullee, Jan-Willem
    Wieringa, Roel J.
    [J]. 2014 IEEE 1ST WORKSHOP ON EVOLVING SECURITY AND PRIVACY REQUIREMENTS ENGINEERING (ESPRE), 2014, : 7 - 12
  • [2] An Argumentation-Based Analysis of the Simonshaven Case
    Prakken, Henry
    [J]. TOPICS IN COGNITIVE SCIENCE, 2020, 12 (04) : 1068 - 1091
  • [3] An Argumentation-based Support System for Requirements Reconciliation
    Mirbel, Isabelle
    Villata, Serena
    [J]. COMPUTATIONAL MODELS OF ARGUMENT, 2014, 266 : 467 - 468
  • [4] Argumentation-Based Legal Requirements Engineering The Role of Legal Interpretation in Requirements Acquisition
    Muthuri, Robert
    Boella, Guido
    Hulstijn, Joris
    Humphreys, Llio
    [J]. 2016 IEEE 24TH INTERNATIONAL REQUIREMENTS ENGINEERING CONFERENCE WORKSHOPS (REW), 2016, : 249 - 258
  • [5] Argumentation-based learning
    Fukumoto, Taro
    Sawamura, Hajime
    [J]. ARGUMENTATION IN MULTI-AGENT SYSTEMS, 2007, 4766 : 17 - +
  • [6] Argumentation-based negotiation
    Rahwan, I
    Ramchurn, SD
    Jennings, NR
    McBurney, P
    Parsons, S
    Sonenberg, L
    [J]. KNOWLEDGE ENGINEERING REVIEW, 2003, 18 (04): : 343 - 375
  • [7] Argumentation-based Policy Analysis for Drone Systems
    Karafili, Erisa
    Lupu, Emil C.
    Arunkumar, Saritha
    Bertino, Elisa
    [J]. 2017 IEEE SMARTWORLD, UBIQUITOUS INTELLIGENCE & COMPUTING, ADVANCED & TRUSTED COMPUTED, SCALABLE COMPUTING & COMMUNICATIONS, CLOUD & BIG DATA COMPUTING, INTERNET OF PEOPLE AND SMART CITY INNOVATION (SMARTWORLD/SCALCOM/UIC/ATC/CBDCOM/IOP/SCI), 2017,
  • [8] Argumentation-based collaborative intelligence analysis in CISpaces
    Toniolo, Alice
    Dropps, Timothy
    Ouyang, Robin Wentao
    Allen, John A.
    Norman, Timothy J.
    Oren, Nir
    Srivastava, Mani
    Sullivan, Paul
    [J]. COMPUTATIONAL MODELS OF ARGUMENT, 2014, 266 : 481 - 482
  • [9] A study of argumentation-based negotiation in collaborative design
    Jin, Yan
    Geslin, Mathieu
    [J]. AI EDAM-ARTIFICIAL INTELLIGENCE FOR ENGINEERING DESIGN ANALYSIS AND MANUFACTURING, 2010, 24 (01): : 35 - 48
  • [10] Argumentation-Based Negotiation? Negotiation-Based Argumentation!
    Landes, Juergen
    Buettner, Ricardo
    [J]. E-COMMERCE AND WEB TECHNOLOGIES, EC-WEB 2012, 2012, 123 : 149 - 162