TUHH Open Research
Help
  • Log In
    New user? Click here to register.Have you forgotten your password?
  • English
  • Deutsch
  • Communities & Collections
  • Publications
  • Research Data
  • People
  • Institutions
  • Projects
  • Statistics
  1. Home
  2. TUHH
  3. Publication References
  4. Flaws in Flows: Unveiling design flaws via information flow analysis
 
Options

Flaws in Flows: Unveiling design flaws via information flow analysis

Publikationstyp
Conference Paper
Date Issued
2019-03
Sprache
English
Author(s)
Tuma, Katja  
Scandariato, Riccardo  
Balliu, Musard  
TORE-URI
http://hdl.handle.net/11420/10258
Start Page
191
End Page
200
Article Number
8703905
Citation
IEEE International Conference on Software Architecture (ICSA 2019)
Contribution to Conference
IEEE International Conference on Software Architecture, ICSA 2019  
Publisher DOI
10.1109/ICSA.2019.00028
Scopus ID
2-s2.0-85065761706
This paper presents a practical and formal approach to analyze security-centric information flow policies at the level of the design model. Specifically, we focus on data confidentiality and data integrity objectives. In its guiding principles, the approach is meant to be amenable for designers (e.g., software architects) that have very limited or no background in formal models, logics, and the like. To this aim, we provide an intuitive graphical notation, which is based on the familiar Data Flow Diagrams, and which requires as little effort as possible in terms of extra security-centric information the designer has to provide. The result of the analysis algorithm is the early discovery of design flaws in the form of violations of the intended security properties. The approach is implemented as a publicly available plugin for Eclipse and evaluated with four real-world case studies from publicly available literature.
Subjects
Confidentiality
Data Flow Diagram
Integrity
Secure design
TUHH
Weiterführende Links
  • Contact
  • Send Feedback
  • Cookie settings
  • Privacy policy
  • Impress
DSpace Software

Built with DSpace-CRIS software - Extension maintained and optimized by 4Science
Design by effective webwork GmbH

  • Deutsche NationalbibliothekDeutsche Nationalbibliothek
  • ORCiD Member OrganizationORCiD Member Organization
  • DataCiteDataCite
  • Re3DataRe3Data
  • OpenDOAROpenDOAR
  • OpenAireOpenAire
  • BASE Bielefeld Academic Search EngineBASE Bielefeld Academic Search Engine
Feedback