TUHH Open Research
Help
  • Log In
    New user? Click here to register.Have you forgotten your password?
  • English
  • Deutsch
  • Communities & Collections
  • Publications
  • Research Data
  • People
  • Institutions
  • Projects
  • Statistics
  1. Home
  2. TUHH
  3. Publication References
  4. Security in context: analysis and refinement of software architectures
 
Options

Security in context: analysis and refinement of software architectures

Publikationstyp
Conference Paper
Date Issued
2010-07
Sprache
English
Author(s)
Heyman, Tom  
Scandariato, Riccardo  
Joosen, Wouter  
TORE-URI
http://hdl.handle.net/11420/14986
Start Page
161
End Page
170
Article Number
5676254
Citation
Proceedings - 34th International Computer Software and Applications Conference : 5676254, 161-170 (2010)
Contribution to Conference
34th IEEE Annual International Computer Software and Applications Conference, COMPSAC 2010  
Publisher DOI
10.1109/COMPSAC.2010.23
Scopus ID
2-s2.0-78751689795
Publisher
IEEE
Security analysis methods can provide correct yet meaningless results if the assumptions underlying the model do not conform to reality. We present an approach to analyze the security of software-intensive system architectures that focusses on making these underlying assumptions explicit, so that they can be taken into account. Starting from an Alloy model of a software architecture, a set of constraints is elicited by leveraging model relaxation techniques. These constraints form a minimal but sufficient condition that the system must meet in order to realise its security requirements. As the approach starts from the minimal guarantees that the system environment offers, it does not depend on an explicit attacker model and can take arbitrary attacker behaviour into account. As it is iterative, it is possible to constructively integrate the approach in a secure software development life cycle. Our results are illustrated by means of a case study.
Subjects
Alloy
Analysis
Security
Software architecture
DDC Class
004: Informatik
TUHH
Weiterführende Links
  • Contact
  • Send Feedback
  • Cookie settings
  • Privacy policy
  • Impress
DSpace Software

Built with DSpace-CRIS software - Extension maintained and optimized by 4Science
Design by effective webwork GmbH

  • Deutsche NationalbibliothekDeutsche Nationalbibliothek
  • ORCiD Member OrganizationORCiD Member Organization
  • DataCiteDataCite
  • Re3DataRe3Data
  • OpenDOAROpenDOAR
  • OpenAireOpenAire
  • BASE Bielefeld Academic Search EngineBASE Bielefeld Academic Search Engine
Feedback