OASIS: Weakening User Obligations for Security-critical Systems

OASIS: Weakening User Obligations for Security-critical Systems
复制标题

OASIS:弱化用户对安全关键系统的义务

DOI:
--
复制
发表时间:
2020
期刊:
IEEE International Requirements Engineering Conference
影响因子:
--
通讯作者:
B. Nuseibeh
B. Nuseibeh
中科院分区:
--
文献类型:
--
作者:
T. Tun;A. Bennaceur;B. Nuseibeh

文献摘要

被引文献

相似文献

安全关键系统通常对其用户的行为提出一些要求,迫使他们在使用这些系统时遵循某些指示。当用户没有完全履行其义务时,可能会出现安全漏洞。在本文中,我们提出了一种方法,提高系统的安全性,确保攻击的情况下减轻,即使用户偏离他们的预期行为。该方法使用结构化的过渡系统来呈现和推理用户义务。其目的是通过削弱对用户行为的假设来识别潜在的漏洞。我们提出了一种算法,结合迭代抽象和控制器合成产生一个新的软件规范,保持满足安全要求,同时削弱用户的义务。我们证明了我们的方法的可行性,通过两个例子,从电子投票和电子商务领域。
Security-critical systems typically place some requirements on the behaviour of their users, obliging them to follow certain instructions when using those systems. Security vulnerabilities can arise when users do not fully satisfy their obligations. In this paper, we propose an approach that improves system security by ensuring that attack scenarios are mitigated even when the users deviate from their expected behaviour. The approach uses structured transition systems to present and reason about user obligations. The aim is to identify potential vulnerabilities by weakening the assumptions on how the user will behave. We present an algorithm that combines iterative abstraction and controller synthesis to produce a new software specification that maintains the satisfaction of security requirements while weakening user obligations. We demonstrate the feasibility of our approach through two examples from the e-voting and e-commerce domains.