Unifying security and software Product family models to enhance information confidentiality
Unifying security and software Product family models to enhance information confidentiality
批准号:
RGPIN-2014-06115
负责人:
Khedri, Ridha
金额:
$1.46万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2017
资助国家:
加拿大
项目状态:
已结题
起止时间:
2017-01-01 至 2018-12-31
中文摘要
由于政府、军队、企业、金融机构、医院和私营企业积累了大量关于其雇员、客户、产品、研究和财务状况的机密信息,因此安全,特别是信息保密对这些企业来说变得越来越重要。到目前为止,安全建模工作在很大程度上独立于系统需求和产品族建模。通常的做法是先对系统需求建模,然后再添加安全性。通常,系统的安全部分覆盖在主要功能的子系统上。将特征建模和其他早期需求模型与保密模型统一起来,以获得产品族及其保密需求的统一视图,是本研究计划的长期目标。目标是获得能够随着软件家族环境中的变化而发展的模型,这将使我们能够生成并传播所需的更改到安全预防和检测机制。因此,我们系统地、快速地加强了软件系列产品对新出现的威胁的响应。本研究将采取以下补充研究方向:1)研究捕获领域和安全知识的模型,以防止通过覆盖通道通信间接泄露未经授权的信息。这个方向将涉及适合于软件系统的代数规范的本体的形式化表示。2)扩展我们早期建立的关于产品族的结果,为特征模型配备一个上下文和环境的表示,在这个环境中,产品族的每个特征都有望进化。此上下文和每个特征环境由域和安全本体捕获。3)探索保密策略的动态实例化和加强信息保密的机制。从安全风险管理人员给出的一套保密规则中,考虑到产品族的安全知识和领域知识,生成(计算)一套更彻底、更完整的规则。所提出的研究将使我们能够拥有能够随环境中的每次变化而动态更新其保密策略和机制的软件系统。安全和软件领域本体将捕获系统环境中的变化,然后正式计算并将一组新的机密规则包含在系统中。我的目标是采用代数方法来正式建模并统一安全性和产品族模型。该方法由于其代数特性,提供了一种生成保密规则和验证统一模型属性的计算方法。此外,它为建模带来了严谨性,并为软件工程培养了一种有纪律的方法来处理安全方面。所提出的计算过程可以很容易地使用计算机代数系统和定理证明器实现自动化。拟议的研究代表了一种在不断变化的世界中加强信息保密的严格方法。获得的结果将为信息安全带来重大贡献,并影响其他使用本体的领域的研究,如商业智能和电子健康。
英文摘要
Security and, in particular, information confidentiality are becoming more and more valuable to governments, military, corporations, financial institutions, hospitals, and private businesses as they amass a great deal of confidential information about their employees, customers, products, research and financial status. So far, security-modeling work has been largely independent of system requirements and product family modeling. It is a common practice to model system requirements first and then security is added as an afterthought. Usually the security part of a system is overlaid on the subsystem of the main functionality. It is the long-term objective of this research program to unify feature modeling and other early requirements models with confidentiality models to gain a unified view of the product family and its confidentiality requirements. The aim is to obtain models that can evolve with the changes in the software family environments, which would enable us generate and propagate the needed changes to the security prevention and detection mechanisms. Consequently, we systematically and quickly strengthen the responses of the products of a software family to emerging threats.The proposed research will take the following complementary research directions: 1) Investigate models that capture the domain and security knowledge in preventing indirect unauthorized information leakage through cover channel communication. This direction will involve a formal representation of an ontology that is suitable for an algebraic specification of software systems. 2) Expand our early-established results on product family to equip feature models with a representation of the context and the environment in which each feature of the family is expected to evolve. This context and each feature environment are captured by the domain and security ontology. 3) Explore dynamic instantiation of confidentiality policy and the mechanisms for enhancing information confidentiality. From a set of confidentiality rules given by the security risk management officers, a more thorough and complete set of rules are generated (calculated) taking into account the security knowledge and domain knowledge of the product family. The proposed research would enable us to have software systems that can on the fly update their confidentiality policy and mechanisms with each change in the environment. The security and software domain ontology will capture changes in the system's environment and then a new set of confidentiality rules will formally be calculated and included in the system. I aim at adopting an algebraic approach to formally model and unify security and product families models. The proposed methodology, due to its algebraic flavor, brings a calculational way to generate confidentiality rules and verification of the properties of the unified model. Moreover, it brings rigor in modeling and fosters a disciplined approach to software engineering to handle security aspects. The proposed calculational processes would be easily automated using computer algebra systems and theorem provers. The proposed research represents a rigorous approach to enhance information confidentially in an ever-changing world. The obtained results would bring major contributions to information security and affect research in other areas that use ontologies such as business intelligence and eHealth.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Ontology-based Approach to Enhance Security in Network Architecture and in System Design
-
批准号:RGPIN-2020-06859
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.75万
-
财政年份:2022
-
负责人:Khedri, Ridha
-
依托单位:
Ontology-based Approach to Enhance Security in Network Architecture and in System Design
-
批准号:RGPIN-2020-06859
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.75万
-
财政年份:2021
-
负责人:Khedri, Ridha
-
依托单位:
Ontology-based Approach to Enhance Security in Network Architecture and in System Design
-
批准号:RGPIN-2020-06859
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.75万
-
财政年份:2020
-
负责人:Khedri, Ridha
-
依托单位:
Unifying security and software Product family models to enhance information confidentiality
-
批准号:RGPIN-2014-06115
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.46万
-
财政年份:2018
-
负责人:Khedri, Ridha
-
依托单位:
Unifying security and software Product family models to enhance information confidentiality
-
批准号:RGPIN-2014-06115
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.46万
-
财政年份:2016
-
负责人:Khedri, Ridha
-
依托单位:
Unifying security and software Product family models to enhance information confidentiality
-
批准号:RGPIN-2014-06115
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.46万
-
财政年份:2015
-
负责人:Khedri, Ridha
-
依托单位:
Unifying security and software Product family models to enhance information confidentiality
-
批准号:RGPIN-2014-06115
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.46万
-
财政年份:2014
-
负责人:Khedri, Ridha
-
依托单位:
Multi-view assessment of security requirements for software product lines
-
批准号:227806-2009
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.38万
-
财政年份:2013
-
负责人:Khedri, Ridha
-
依托单位:
Multi-view assessment of security requirements for software product lines
-
批准号:227806-2009
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.38万
-
财政年份:2012
-
负责人:Khedri, Ridha
-
依托单位:
Multi-view assessment of security requirements for software product lines
-
批准号:227806-2009
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.38万
-
财政年份:2011
-
负责人:Khedri, Ridha
-
依托单位:
Multi-view assessment of security requirements for software product lines
-
批准号:227806-2009
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.38万
-
财政年份:2010
-
负责人:Khedri, Ridha
-
依托单位:
Multi-view assessment of security requirements for software product lines
-
批准号:227806-2009
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.38万
-
财政年份:2009
-
负责人:Khedri, Ridha
-
依托单位:
Software functional requirements specification decomposition: architectural design and system-testing driven approaches
-
批准号:227806-2004
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.44万
-
财政年份:2008
-
负责人:Khedri, Ridha
-
依托单位:
Software functional requirements specification decomposition: architectural design and system-testing driven approaches
-
批准号:227806-2004
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.44万
-
财政年份:2007
-
负责人:Khedri, Ridha
-
依托单位:
Software functional requirements specification decomposition: architectural design and system-testing driven approaches
-
批准号:227806-2004
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.44万
-
财政年份:2006
-
负责人:Khedri, Ridha
-
依托单位:
Software functional requirements specification decomposition: architectural design and system-testing driven approaches
-
批准号:227806-2004
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.44万
-
财政年份:2005
-
负责人:Khedri, Ridha
-
依托单位:
Software functional requirements specification decomposition: architectural design and system-testing driven approaches
-
批准号:227806-2004
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.44万
-
财政年份:2004
-
负责人:Khedri, Ridha
-
依托单位:
Using sequential and concurrent scenarios in the software requirements activities: a relational approach
-
批准号:227806-2000
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.09万
-
财政年份:2003
-
负责人:Khedri, Ridha
-
依托单位:
Using sequential and concurrent scenarios in the software requirements activities: a relational approach
-
批准号:227806-2000
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.09万
-
财政年份:2002
-
负责人:Khedri, Ridha
-
依托单位:
Using sequential and concurrent scenarios in the software requirements activities: a relational approach
-
批准号:227806-2000
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.09万
-
财政年份:2001
-
负责人:Khedri, Ridha
-
依托单位:
国内基金
海外基金
黄淮海平原典型区域土壤盐渍化演变机制与发生风险防控对策研究
-
批准号:41171178
-
项目类别:面上项目
-
资助金额:65.0万元
-
批准年份:2011
-
负责人:刘广明
-
依托单位:
存储安全中介系统理论、仿真和实现技术研究
-
批准号:61070154
-
项目类别:面上项目
-
资助金额:30.0万元
-
批准年份:2010
-
负责人:韩德志
-
依托单位:
最优证券设计及完善中国资本市场的路径选择
-
批准号:70873012
-
项目类别:面上项目
-
资助金额:27.0万元
-
批准年份:2008
-
负责人:彭龙
-
依托单位: