Security in Context: Analysis and Refinement of Software Architectures

Security in Context: Analysis and Refinement of Software Architectures
复制标题

DOI:
10.1109/compsac.2010.23
复制
发表时间:
2010-07
期刊:
2010 IEEE 34th Annual Computer Software and Applications Conference
影响因子:
--
通讯作者:
Thomas Heyman;R. Scandariato;W. Joosen
Thomas Heyman;R. Scandariato;W. Joosen
中科院分区:
其他
文献类型:
--
作者:
Thomas Heyman;R. Scandariato;W. Joosen

文献摘要

被引文献

相似文献

如果模型的假设不符合实际情况,证券分析方法可能提供正确但无意义的结果。我们提出了一种方法来分析软件密集型系统架构的安全性,该方法侧重于明确这些潜在的假设,以便将它们考虑在内。从软件体系结构的Alloy模型开始,通过利用模型松弛技术得到一组约束。这些约束构成了系统必须满足的最小但充分的条件,以实现其安全要求。由于该方法从系统环境提供的最小保证开始,因此它不依赖于显式攻击者模型,并且可以考虑任意的攻击者行为。由于它是迭代的,因此可以建设性地将该方法集成到安全的软件开发生命周期中。我们的研究结果通过一个案例加以说明。
Security analysis methods can provide correct yet meaningless results if the assumptions underlying the model do not conform to reality. We present an approach to analyze the security of software-intensive system architectures that focusses on making these underlying assumptions explicit, so that they can be taken into account. Starting from an Alloy model of a software architecture, a set of constraints is elicited by leveraging model relaxation techniques. These constraints form a minimal but sufficient condition that the system must meet in order to realise its security requirements. As the approach starts from the minimal guarantees that the system environment offers, it does not depend on an explicit attacker model and can take arbitrary attacker behaviour into account. As it is iterative, it is possible to constructively integrate the approach in a secure software development life cycle. Our results are illustrated by means of a case study.