A novel Security-by-Design methodology: Modeling and assessing security by SLAs with a quantitative approach

A novel Security-by-Design methodology: Modeling and assessing security by SLAs with a quantitative approach
复制标题

一种新颖的设计安全方法:使用定量方法按 SLA 建模和评估安全性

DOI:
10.1016/j.jss.2020.110537
复制
发表时间:
2020
期刊:
J. Syst. Softw.
影响因子:
--
通讯作者:
Umberto Villano
Umberto Villano
中科院分区:
--
文献类型:
--
作者:
V. Casola;Alessandra De Benedictis;M. Rak;Umberto Villano

文献摘要

被引文献

相似文献

最近的软件开发方法,如DevOps或敏捷,非常流行和广泛使用,特别是用于云服务和应用程序的开发。它们大大缩短了开发软件的上市时间,但与此同时,它们很难与安全设计和风险管理方法相结合。由于开发团队中需要安全专家,以及缺乏自动工具来评估风险并在设计和运营阶段评估安全性,这些都不容易实现自动化,并且需要大量的经济投资。本文提出了一种新的安全设计方法的基础上的安全服务水平协议(SLA),它可以集成在现代开发流程,并能够支持风险管理生命周期中几乎完全自动化的方式。特别是,它依赖于一个引导的风险分析过程和一个完全自动化的安全评估阶段,这使得能够评估云应用程序授予的安全属性,并在安全SLA中报告它们。我们验证了所提出的方法与一个真实的案例研究,这表明其有效性,提高了安全方面的设计师和开发团队的认识,并在减少安全的设计过程中的时间。
Recent software development methodologies, as DevOps or Agile, are very popular and widely used, especially for the development of cloud services and applications. They dramatically reduce the time-to-market of developed software but, at the same time, they can be hardly integrated with security design and risk management methodologies. These cannot be easily automated and require big economic investments, due to the necessity of security experts in the development team and to the lack of automatic tools to evaluate risk and to assess security in the design and operation phases. This paper presents a novel Security-by-Design methodology based on Security Service Level Agreements (SLAs), which can be integrated within modern development processes and that is able to support the risk management life-cycle in an almost-completely automated way. In particular, it relies upon a guided risk analysis process and a completely automated security assessment phase, which enable to assess the security properties granted by a cloud application and to report them in a Security SLA. We validated the proposed methodology with respect to a real case study, which showed its effectiveness in improving the awareness of designer and developer teams on security aspects and in reducing the secure design process time.