Aspect-Oriented Security Hardening of Design Models
设计模型面向方面的安全强化
基本信息
- 批准号:183938-2012
- 负责人:
- 金额:$ 2.48万
- 依托单位:
- 依托单位国家:加拿大
- 项目类别:Discovery Grants Program - Individual
- 财政年份:2015
- 资助国家:加拿大
- 起止时间:2015-01-01 至 2016-12-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Software security becomes increasingly important. Nevertheless, it is very often considered as an afterthought phase of the development life cycle. However, given the complexity and pervasiveness of modern software systems, addressing security later in the development process leads to huge cost in retrofitting security into the software and further can introduce additional vulnerabilities. Therefore, security must be considered early during the engineering process. To this end, a promising approach is to adopt the emerging Model Driven Architecture (MDA) paradigm and the prominent modeling languages, such as the Unified Modeling Language (UML) and the Systems Modeling Language (SysML), in order to address security throughout the development life cycle. Furthermore, security is a crosscutting concern that pervades the entire software. The manual addition of security features into design models, especially for large scale software, often leads to scattered security features tangled in the main functionality. Additionally, adding security manually is tedious and generally may lead to other security flaws. A promising approach is to consider Aspect-Oriented Modeling (AOM) as a mechanism for security specification and injection at the software design phase. In recent years, AOM has become the focus of many research initiatives. However, the majority of these proposals are presented from a practical perspective. In addition, very few proposals leveraged AOM to address security. As such, our proposal aims to elaborate a practical and a formal framework for the security hardening of design models. In particular, the targeted objectives are the following: (1) Design an algebra of pointcut/advice primitives to specify security concerns on design models, (2) devise an AOM security profile that leverages the aforementioned algebra, (3) elaborate semantic definitions for matching and weaving for the profile constructs, (4) derive, from the semantic definitions, matching and weaving algorithms that will be used to design and implement an environment for the specification and injection of security aspects within design models, (5) conduct real-life case studies to validate the importance, relevance and practicality of the proposed framework.
软件安全变得越来越重要。然而,它经常被认为是开发生命周期的一个事后考虑阶段。然而,考虑到现代软件系统的复杂性和普遍性,在开发过程的后期处理安全性会导致在将安全性改造到软件中时花费巨大的成本,并且进一步可能引入额外的漏洞。因此,在工程过程中必须尽早考虑安全性。为此,一个有希望的方法是采用新兴的模型驱动体系结构(MDA)范例和突出的建模语言,例如统一建模语言(UML)和系统建模语言(SysML),以便在整个开发生命周期中解决安全性问题。此外,安全性是贯穿整个软件的横切关注点。手工将安全特性添加到设计模型中,特别是对于大型软件,往往会导致分散的安全特性纠缠在主要功能中。此外,手动添加安全性是乏味的,通常可能导致其他安全性缺陷。一种很有前途的方法是将面向方面的建模(AOM)视为软件设计阶段的安全规范和注入机制。近年来,AOM已成为许多研究的焦点。然而,这些建议大多是从实际的角度提出的。此外,很少有提案利用AOM来解决安全性问题。因此,我们的建议旨在为设计模型的安全加固精心设计一个实用的和正式的框架。具体而言,目标如下:(1)设计切入点/通知原语的代数,以指定设计模型上的安全关注点;(2)设计利用上述代数的AOM安全概要文件;(3)为概要文件构造的匹配和编织精心设计语义定义;(4)从语义定义中派生匹配和编织算法,这些算法将用于设计和实现设计模型中安全方面的规范和注入的环境。(5)进行现实案例研究,以验证所提出框架的重要性、相关性和实用性。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Debbabi, Mourad其他文献
CASeS: Concurrent Contingency Analysis-Based Security Metric Deployment for the Smart Grid
- DOI:
10.1109/tsg.2019.2959937 - 发表时间:
2020-05-01 - 期刊:
- 影响因子:9.6
- 作者:
Akaber, Parisa;Moussa, Bassam;Debbabi, Mourad - 通讯作者:
Debbabi, Mourad
A Detection and Mitigation Model for PTP Delay Attack in an IEC 61850 Substation
- DOI:
10.1109/tsg.2016.2644618 - 发表时间:
2018-09-01 - 期刊:
- 影响因子:9.6
- 作者:
Moussa, Bassani;Debbabi, Mourad;Assi, Chadi - 通讯作者:
Assi, Chadi
Fingerprinting Android packaging: Generating DNAs for malware detection
- DOI:
10.1016/j.diin.2016.04.013 - 发表时间:
2016-08-07 - 期刊:
- 影响因子:0
- 作者:
Karbab, ElMouatez Billah;Debbabi, Mourad;Mouheb, Djedjiga - 通讯作者:
Mouheb, Djedjiga
A unified data mining solution for authorship analysis in anonymous textual communications
- DOI:
10.1016/j.ins.2011.03.006 - 发表时间:
2013-05-10 - 期刊:
- 影响因子:8.1
- 作者:
Iqbal, Farkhund;Binsalleeh, Hamad;Debbabi, Mourad - 通讯作者:
Debbabi, Mourad
Cyber Scanning: A Comprehensive Survey
- DOI:
10.1109/surv.2013.102913.00020 - 发表时间:
2014-01-01 - 期刊:
- 影响因子:35.6
- 作者:
Bou-Harb, Elias;Debbabi, Mourad;Assi, Chadi - 通讯作者:
Assi, Chadi
Debbabi, Mourad的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Debbabi, Mourad', 18)}}的其他基金
Fingerprinting and Big Data Security Analytics for the Scalable Generation of Cyber Threat Intelligence
用于可扩展生成网络威胁情报的指纹识别和大数据安全分析
- 批准号:
RGPIN-2017-06650 - 财政年份:2022
- 资助金额:
$ 2.48万 - 项目类别:
Discovery Grants Program - Individual
Fingerprinting and Big Data Security Analytics for the Scalable Generation of Cyber Threat Intelligence
用于可扩展生成网络威胁情报的指纹识别和大数据安全分析
- 批准号:
RGPIN-2017-06650 - 财政年份:2021
- 资助金额:
$ 2.48万 - 项目类别:
Discovery Grants Program - Individual
NSERC/Hydro-Québec/Thales Industrial Research Chair in Smart Grid Security: Detection, Prevention, Mitigation and Recovery from Cyber-Physical Attacks
NSERC/Hydro-Québec/Thales 智能电网安全工业研究主席:网络物理攻击的检测、预防、缓解和恢复
- 批准号:
501621-2015 - 财政年份:2020
- 资助金额:
$ 2.48万 - 项目类别:
Industrial Research Chairs
Fingerprinting and Big Data Security Analytics for the Scalable Generation of Cyber Threat Intelligence
用于可扩展生成网络威胁情报的指纹识别和大数据安全分析
- 批准号:
RGPIN-2017-06650 - 财政年份:2020
- 资助金额:
$ 2.48万 - 项目类别:
Discovery Grants Program - Individual
Fingerprinting and Big Data Security Analytics for the Scalable Generation of Cyber Threat Intelligence
用于可扩展生成网络威胁情报的指纹识别和大数据安全分析
- 批准号:
DGDND-2017-00016 - 财政年份:2019
- 资助金额:
$ 2.48万 - 项目类别:
DND/NSERC Discovery Grant Supplement
Fingerprinting and Big Data Security Analytics for the Scalable Generation of Cyber Threat Intelligence
用于可扩展生成网络威胁情报的指纹识别和大数据安全分析
- 批准号:
RGPIN-2017-06650 - 财政年份:2019
- 资助金额:
$ 2.48万 - 项目类别:
Discovery Grants Program - Individual
NSERC/Hydro-Québec/Thales Industrial Research Chair in Smart Grid Security: Detection, Prevention, Mitigation and Recovery from Cyber-Physical Attacks
NSERC/Hydro-Québec/Thales 智能电网安全工业研究主席:网络物理攻击的检测、预防、缓解和恢复
- 批准号:
501621-2015 - 财政年份:2019
- 资助金额:
$ 2.48万 - 项目类别:
Industrial Research Chairs
Fingerprinting and Big Data Security Analytics for the Scalable Generation of Cyber Threat Intelligence
用于可扩展生成网络威胁情报的指纹识别和大数据安全分析
- 批准号:
DGDND-2017-00016 - 财政年份:2018
- 资助金额:
$ 2.48万 - 项目类别:
DND/NSERC Discovery Grant Supplement
Fingerprinting and Big Data Security Analytics for the Scalable Generation of Cyber Threat Intelligence
用于可扩展生成网络威胁情报的指纹识别和大数据安全分析
- 批准号:
RGPIN-2017-06650 - 财政年份:2018
- 资助金额:
$ 2.48万 - 项目类别:
Discovery Grants Program - Individual
Connect Internet of Things Research
连接物联网研究
- 批准号:
534119-2018 - 财政年份:2018
- 资助金额:
$ 2.48万 - 项目类别:
Connect Grants Level 2
相似国自然基金
炭包覆纳米晶的"Oriented Attachment"生长及其多维结构构筑
- 批准号:51572015
- 批准年份:2015
- 资助金额:64.0 万元
- 项目类别:面上项目
相似海外基金
Travel: NSF Student Travel Grant for 2023 IEEE International Symposium on Hardware Oriented Security and Trust (HOST)
差旅费:2023 年 IEEE 面向硬件的安全与信任国际研讨会 (HOST) 的 NSF 学生差旅补助金
- 批准号:
2321803 - 财政年份:2023
- 资助金额:
$ 2.48万 - 项目类别:
Standard Grant
SaTC: EDU: Building a Cyber Security Enhanced Education Laboratory for Hands-on Experience Oriented Cybersecurity Education
SaTC:EDU:建立网络安全增强教育实验室,以实现面向实践的网络安全教育
- 批准号:
2154606 - 财政年份:2022
- 资助金额:
$ 2.48万 - 项目类别:
Standard Grant
Human-oriented computer security
以人为本的计算机安全
- 批准号:
RGPIN-2017-06273 - 财政年份:2022
- 资助金额:
$ 2.48万 - 项目类别:
Discovery Grants Program - Individual
Travel: NSF Student Travel Grant for 2022 IEEE International Symposium on Hardware Oriented Security and Trust (HOST)
差旅费:2022 年 IEEE 面向硬件的安全与信任国际研讨会 (HOST) 的 NSF 学生差旅补助金
- 批准号:
2224111 - 财政年份:2022
- 资助金额:
$ 2.48万 - 项目类别:
Standard Grant
Human Oriented Computer Security
以人为本的计算机安全
- 批准号:
CRC-2016-00049 - 财政年份:2021
- 资助金额:
$ 2.48万 - 项目类别:
Canada Research Chairs
Human-oriented computer security
以人为本的计算机安全
- 批准号:
RGPIN-2017-06273 - 财政年份:2021
- 资助金额:
$ 2.48万 - 项目类别:
Discovery Grants Program - Individual
Human Oriented Computer Security
以人为本的计算机安全
- 批准号:
CRC-2016-00049 - 财政年份:2020
- 资助金额:
$ 2.48万 - 项目类别:
Canada Research Chairs
Human-oriented computer security
以人为本的计算机安全
- 批准号:
RGPIN-2017-06273 - 财政年份:2020
- 资助金额:
$ 2.48万 - 项目类别:
Discovery Grants Program - Individual
Human-oriented computer security
以人为本的计算机安全
- 批准号:
507902-2017 - 财政年份:2019
- 资助金额:
$ 2.48万 - 项目类别:
Discovery Grants Program - Accelerator Supplements
Capacity-oriented approaches to food security, diet quality, and cardiovascular disease risk among Hispanics/Latinos
针对西班牙裔/拉丁裔的粮食安全、饮食质量和心血管疾病风险采取以能力为导向的方法
- 批准号:
10318185 - 财政年份:2019
- 资助金额:
$ 2.48万 - 项目类别: