Enforcing a security pattern in stakeholder goal models

Enforcing a security pattern in stakeholder goal models
复制标题

DOI:
10.1145/1456362.1456366
复制
发表时间:
2008-10
期刊:
--
影响因子:
--
通讯作者:
Y. Yu;H. Kaiya;H. Washizaki;Yingfei Xiong;Zhenjiang Hu;Nobukazu Yoshioka
Y. Yu;H. Kaiya;H. Washizaki;Yingfei Xiong;Zhenjiang Hu;Nobukazu Yoshioka
中科院分区:
其他
文献类型:
--
作者:
Y. Yu;H. Kaiya;H. Washizaki;Yingfei Xiong;Zhenjiang Hu;Nobukazu Yoshioka

文献摘要

相似文献

模式是关于反复出现的问题和解决方案的有用知识。使用需求模型中的模式检测安全问题可能会导致其早期解决方案。为了促进安全问题的早期检测和解决,在本文中,我们将基于角色的访问控制(RBAC)正式描述为可能出现在涉众需求模型中的模式。我们还在面向目标的建模工具中使用模型驱动的查询和转换实现了正式描述的模式。将该工具应用于文献中发表的许多需求模型,可以在几个面向目标的涉众需求中自动检测和解决安全模式。
Patterns are useful knowledge about recurring problems and solutions. Detecting a security problem using patterns in requirements models may lead to its early solution. In order to facilitate early detection and resolution of security problems, in this paper, we formally describe a role-based access control (RBAC) as a pattern that may occur in stakeholder requirements models. We also implemented in our goal-oriented modeling tool the formally described pattern using model-driven queries and transformations. Applied to a number of requirements models published in literature, the tool automates the detection and resolution of the security pattern in several goal-oriented stakeholder requirements.