Enterprise security pattern: A model-driven architecture instance

被引:9
|
作者
Moral-Garcia, Santiago [1 ,2 ]
Moral-Rubio, Santiago [3 ]
Fernandez, Eduardo B. [4 ]
Fernandez-Medina, Eduardo [5 ]
机构
[1] Santander Bank, Produban, Boston, MA USA
[2] Rey Juan Carlos Univ, Kybele Res Grp, Dept Comp Languages & Syst 2, Madrid, Spain
[3] BBVA Grp, Madrid, Spain
[4] Florida Atlantic Univ, Secure Syst Res Grp, Dept Comp & Elect Eng & Comp Sci, Boca Raton, FL 33431 USA
[5] Univ Castilla La Mancha, GSyA Res Grp, Dept Informat Technol & Syst, E-13071 Ciudad Real, Spain
关键词
Secure cloud computing; Model driven architecture; Enterprise security architecture; Security pattern; Enterprise security pattern;
D O I
10.1016/j.csi.2013.12.009
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
To secure their information assets, organizations should seek support from enterprise security architectures. Security patterns are a good way to build and test new security mechanisms, but they have some limitations related to their usability. In previous work, we defined a new type of security pattern called Enterprise Security Pattern. The main objective of these patterns is to provide an instance of model-driven architecture, which offers a solution to recurring problems that have to do with information systems security. In recent years, the hiring of Software as a Service (SaaS) from cloud providers has become very popular. There seem to be many advantages of using these services, but organizations need to be aware of a variety of threats, as well as being prepared to handle them. In another work undertaken previously, we defined an enterprise security pattern called Secure Software as a Service (Secure SaaS), which the organizations could apply to protect their information assets when using SaaS. In this paper, we present different instances of the solution models of the enterprise security pattern Secure SaaS, aiming to verify the risks that an organization would assume if each of the instances were deployed. With this approach, we intend to show how the design decisions adopted when performing the transformations between the solution models can have a direct impact on the security provided by the pattern. (C) 2013 Published by Elsevier B.V.
引用
收藏
页码:748 / 758
页数:11
相关论文
共 50 条
  • [1] Model-driven architecture based security analysis
    Mili, Saoussen
    Nguyen, Nga
    Chelouah, Rachid
    [J]. SYSTEMS ENGINEERING, 2021, 24 (05) : 307 - 321
  • [2] ModelSec: A Generative Architecture for Model-Driven Security
    Sanchez, Oscar
    Molina, Fernando
    Garcia-Molina, Jesus
    Toval, Ambrosio
    [J]. JOURNAL OF UNIVERSAL COMPUTER SCIENCE, 2009, 15 (15) : 2957 - 2980
  • [3] Model-driven security based on a Web services security architecture
    Nakamura, Y
    Tatsubori, M
    Imamura, T
    Ono, K
    [J]. 2005 IEEE INTERNATIONAL CONFERENCE ON SERVICES COMPUTING, VOL 1, PROCEEDINGS, 2005, : 7 - 15
  • [4] Model-Driven Architecture
    Venegas Loor, Leopoldo Vinicio
    [J]. REVISTA SAN GREGORIO, 2014, (08): : 64 - 72
  • [5] The rise of the model-driven enterprise
    Cohn, D
    Stolze, M
    [J]. PROCEEDINGS OF THE IEEE INTERNATIONAL CONFERENCE ON E-COMMERCE TECHNOLOGY FOR DYNAMIC E-BUSINESS, 2004, : 324 - 327
  • [6] A Conceptual Blueprint for Enterprise Architecture Model-Driven Business Process Optimization
    Ori, Dora
    Szabo, Zoltan
    [J]. BUSINESS PROCESS MANAGEMENT: BLOCKCHAIN AND CENTRAL AND EASTERN EUROPE FORUM, 2019, 361 : 234 - 248
  • [7] Model-Driven Security Smell Resolution in Microservice Architecture Using LEMMA
    Wizenty, Philip
    Ponce, Francisco
    Rademacher, Florian
    Soldani, Jacopo
    Astudillo, Hernan
    Brogi, Antonio
    Sachweh, Sabine
    [J]. SOFTWARE TECHNOLOGIES, ICSOFT 2023, 2024, 2104 : 29 - 49
  • [8] Advances in Model-Driven Security
    Lucio, Levi
    Zhang, Qin
    Nguyen, Phu H.
    Amrani, Moussa
    Klein, Jacques
    Vangheluwe, Hans
    Le Traon, Yves
    [J]. ADVANCES IN COMPUTERS, VOL 93, 2014, 93 : 103 - 152
  • [9] Model-driven development of enterprise applications
    Kulkarni, V
    Reddy, S
    [J]. UML MODELING LANGUAGES AND APPLICATIONS, 2005, 3297 : 118 - 128
  • [10] Model-driven engineering for the social enterprise
    Grundy, John
    [J]. PROCEEDINGS OF THE 2015 IEEE 19TH INTERNATIONAL ENTERPRISE DISTRIBUTED OBJECT COMPUTING CONFERENCE, 2015, : 39 - 39