A Review of Security Requirements Engineering Methods with Respect to Risk Analysis and Model-Driven Engineering

被引:0
|
作者
Munante, Denisse [1 ]
Chiprianov, Vanea [1 ]
Gallon, Laurent [1 ]
Aniorte, Philippe [1 ]
机构
[1] LIUPPA Univ Pau, Pau, France
关键词
Security requirements engineering; risk analysis; model-driven engineering; review; FRAMEWORK; TROPOS;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
One of the most important aspects that help improve the quality and cost of secure information systems in their early stages of the development lifecycle is Security Requirements Engineering (SRE). However, obtaining such requirements is non-trivial. One domain dealing also with eliciting security requirements is Risk Analysis (RA). Therefore, we perform a review of SRE methods in order to analyse which ones are compatible with RA processes. Moreover, the transition from these early security requirements to security policies at later stages in the lifecycle is generally non-automatic, informal and incomplete. To deal with such issues, model-driven engineering (MDE) uses formal models and automatic model transformations. Therefore, we also review which SRE methods are compatible with MDE approaches. Consequently, our review is based on criteria derived partially from existing survey works, further enriched and specialized in order to evaluate the compatibility of SRE methods with the disciplines of RA and MDE. It summarizes the evidence regarding this issue so as to improve understanding and facilitate evaluating and selecting SRE methods.
引用
收藏
页码:79 / 93
页数:15
相关论文
共 50 条
  • [31] Model-Driven Useware Engineering
    Meixner, Gerrit
    Seissler, Marc
    Breiner, Kai
    [J]. MODEL-DRIVEN DEVELOPMENT OF ADVANCED USER INTERFACES, 2011, 340 : 1 - +
  • [32] Model-driven ontology engineering
    Pan, Yue
    Xie, Guotong
    Ma, Li
    Yang, Yang
    Qiu, ZhaoMing
    Lee, Juhnyoung
    [J]. JOURNAL ON DATA SEMANTICS VII, 2006, 4244 : 57 - 78
  • [33] Model Patches in Model-Driven Engineering
    Cicchetti, Antonio
    Di Ruscio, Davide
    Pierantonio, Alfonso
    [J]. MODELS IN SOFTWARE ENGINEERING, 2010, 6002 : 190 - +
  • [34] A model-driven engineering approach to requirements engineering - How these disciplines may benefit each other
    Moros, Begona
    Vicente-Chicote, Cristina
    Toval, Ambrosio
    [J]. ICSOFT 2007: PROCEEDINGS OF THE SECOND INTERNATIONAL CONFERENCE ON SOFTWARE AND DATA TECHNOLOGIES, VOL SE: SOFTWARE ENGINEERING, 2007, : 296 - +
  • [35] INCORPORATING USABILITY REQUIREMENTS IN A TEST/MODEL-DRIVEN WEB ENGINEERING APPROACH
    Robles Luna, Esteban
    Ignacio Panach, Jose
    Grigera, Julian
    Rossi, Gustavo
    Pastor, Oscar
    [J]. JOURNAL OF WEB ENGINEERING, 2010, 9 (02): : 132 - 156
  • [36] A Controlled Natural Language Approach for Integrating Requirements and Model-Driven Engineering
    Ferreira, David de Almeida
    da Silva, Alberto Rodrigues
    [J]. 2009 FOURTH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING ADVANCES (ICSEA 2009), 2009, : 518 - 523
  • [37] Teaching modelling for requirements engineering and model-driven software development courses
    Berre, Arne J.
    Huang, Shihong
    Murad, Hani
    Alibakhsh, Hanieh
    [J]. COMPUTER SCIENCE EDUCATION, 2018, 28 (01) : 42 - 64
  • [38] 13th Model-Driven Requirements Engineering (MoDRE) Workshop
    Moreira, Ana
    Araujo, Joao
    Mussbacher, Gunter
    Sanchez, Pablo
    [J]. 2023 IEEE 31ST INTERNATIONAL REQUIREMENTS ENGINEERING CONFERENCE WORKSHOPS, REW, 2023, : 245 - 246
  • [39] Industrial Requirements for Supporting AI-Enhanced Model-Driven Engineering
    Bergelin, Johan
    Strandberg, Per Erik
    [J]. ACM/IEEE 25TH INTERNATIONAL CONFERENCE ON MODEL DRIVEN ENGINEERING LANGUAGES AND SYSTEMS, MODELS 2022 COMPANION, 2022, : 375 - 379
  • [40] Fitting schedulability analysis theory into model-driven engineering
    Bordin, Matteo
    Panunzio, Marco
    Vardanega, Tullio
    [J]. ECRTS 2008: PROCEEDINGS OF THE 20TH EUROMICRO CONFERENCE ON REAL-TIME SYSTEMS, 2008, : 135 - 144