Aspect-Oriented Security Hardening of Design Models
Aspect-Oriented Security Hardening of Design Models
批准号:
183938-2012
负责人:
Debbabi, Mourad
金额:
$2.48万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2016
资助国家:
加拿大
项目状态:
已结题
起止时间:
2016-01-01 至 2017-12-31
中文摘要
软件安全变得越来越重要。然而,它经常被认为是开发生命周期中的一个事后阶段。然而,考虑到现代软件系统的复杂性和普遍性,在开发过程后期解决安全问题会导致在软件中改造安全性的巨大成本,并进一步引入额外的漏洞。因此,在工程设计过程中必须及早考虑安全性。为此,一个有前途的方法是采用新兴的模型驱动架构(MDA)范式和突出的建模语言,如统一建模语言(UML)和系统建模语言(SysML),以解决整个开发生命周期的安全性。此外,安全性是贯穿整个软件的横切关注点。将安全特性手动添加到设计模型中,特别是对于大型软件,通常会导致分散的安全特性与主要功能纠缠在一起。此外,手动添加安全性是繁琐的,并且通常可能导致其他安全缺陷。一个很有前途的方法是考虑AOM作为一种机制,在软件设计阶段的安全规范和注入。近年来,AOM已成为许多研究计划的焦点。然而,这些建议大多是从实际角度提出的。此外,利用AOM解决安全问题的提案很少。因此,我们的建议旨在制定一个实用的和正式的框架,设计模型的安全加固。具体而言,有针对性的目标如下:(1)设计切入点/建议原语的代数,以指定设计模型上的安全关注点,(2)设计利用上述代数的AOM安全概要,(3)详细说明用于概要构造的匹配和编织的语义定义,(4)从语义定义中导出,匹配和编织算法,将用于设计和实现一个环境,规范和注入的安全方面的设计模型,(5)进行现实生活中的案例研究,以验证的重要性,相关性和实用性的建议框架。
英文摘要
Software security becomes increasingly important. Nevertheless, it is very often considered as an afterthought phase of the development life cycle. However, given the complexity and pervasiveness of modern software systems, addressing security later in the development process leads to huge cost in retrofitting security into the software and further can introduce additional vulnerabilities. Therefore, security must be considered early during the engineering process. To this end, a promising approach is to adopt the emerging Model Driven Architecture (MDA) paradigm and the prominent modeling languages, such as the Unified Modeling Language (UML) and the Systems Modeling Language (SysML), in order to address security throughout the development life cycle. Furthermore, security is a crosscutting concern that pervades the entire software. The manual addition of security features into design models, especially for large scale software, often leads to scattered security features tangled in the main functionality. Additionally, adding security manually is tedious and generally may lead to other security flaws. A promising approach is to consider Aspect-Oriented Modeling (AOM) as a mechanism for security specification and injection at the software design phase. In recent years, AOM has become the focus of many research initiatives. However, the majority of these proposals are presented from a practical perspective. In addition, very few proposals leveraged AOM to address security. As such, our proposal aims to elaborate a practical and a formal framework for the security hardening of design models. In particular, the targeted objectives are the following: (1) Design an algebra of pointcut/advice primitives to specify security concerns on design models, (2) devise an AOM security profile that leverages the aforementioned algebra, (3) elaborate semantic definitions for matching and weaving for the profile constructs, (4) derive, from the semantic definitions, matching and weaving algorithms that will be used to design and implement an environment for the specification and injection of security aspects within design models, (5) conduct real-life case studies to validate the importance, relevance and practicality of the proposed framework.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Fingerprinting and Big Data Security Analytics for the Scalable Generation of Cyber Threat Intelligence
-
批准号:RGPIN-2017-06650
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$3.64万
-
财政年份:2022
-
负责人:Debbabi, Mourad
-
依托单位:
Fingerprinting and Big Data Security Analytics for the Scalable Generation of Cyber Threat Intelligence
-
批准号:RGPIN-2017-06650
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$3.64万
-
财政年份:2021
-
负责人:Debbabi, Mourad
-
依托单位:
NSERC/Hydro-Québec/Thales Industrial Research Chair in Smart Grid Security: Detection, Prevention, Mitigation and Recovery from Cyber-Physical Attacks
-
批准号:501621-2015
-
项目类别:Industrial Research Chairs
-
资助金额:$12.75万
-
财政年份:2020
-
负责人:Debbabi, Mourad
-
依托单位:
Fingerprinting and Big Data Security Analytics for the Scalable Generation of Cyber Threat Intelligence
-
批准号:RGPIN-2017-06650
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$3.64万
-
财政年份:2020
-
负责人:Debbabi, Mourad
-
依托单位:
Fingerprinting and Big Data Security Analytics for the Scalable Generation of Cyber Threat Intelligence
-
批准号:DGDND-2017-00016
-
项目类别:DND/NSERC Discovery Grant Supplement
-
资助金额:$2.91万
-
财政年份:2019
-
负责人:Debbabi, Mourad
-
依托单位:
Fingerprinting and Big Data Security Analytics for the Scalable Generation of Cyber Threat Intelligence
-
批准号:RGPIN-2017-06650
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$3.64万
-
财政年份:2019
-
负责人:Debbabi, Mourad
-
依托单位:
NSERC/Hydro-Québec/Thales Industrial Research Chair in Smart Grid Security: Detection, Prevention, Mitigation and Recovery from Cyber-Physical Attacks
-
批准号:501621-2015
-
项目类别:Industrial Research Chairs
-
资助金额:$12.75万
-
财政年份:2019
-
负责人:Debbabi, Mourad
-
依托单位:
Fingerprinting and Big Data Security Analytics for the Scalable Generation of Cyber Threat Intelligence
-
批准号:DGDND-2017-00016
-
项目类别:DND/NSERC Discovery Grant Supplement
-
资助金额:$2.91万
-
财政年份:2018
-
负责人:Debbabi, Mourad
-
依托单位:
Fingerprinting and Big Data Security Analytics for the Scalable Generation of Cyber Threat Intelligence
-
批准号:RGPIN-2017-06650
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$3.64万
-
财政年份:2018
-
负责人:Debbabi, Mourad
-
依托单位:
Connect Internet of Things Research
-
批准号:534119-2018
-
项目类别:Connect Grants Level 2
-
资助金额:$0.22万
-
财政年份:2018
-
负责人:Debbabi, Mourad
-
依托单位:
NSERC/Hydro-Québec/Thales Industrial Research Chair in Smart Grid Security: Detection, Prevention, Mitigation and Recovery from Cyber-Physical Attacks
-
批准号:501621-2015
-
项目类别:Industrial Research Chairs
-
资助金额:$12.75万
-
财政年份:2018
-
负责人:Debbabi, Mourad
-
依托单位:
NSERC/Hydro-Québec/Thales Industrial Research Chair in Smart Grid Security: Detection, Prevention, Mitigation and Recovery from Cyber-Physical Attacks
-
批准号:501621-2015
-
项目类别:Industrial Research Chairs
-
资助金额:$10.93万
-
财政年份:2017
-
负责人:Debbabi, Mourad
-
依托单位:
Fingerprinting and Big Data Security Analytics for the Scalable Generation of Cyber Threat Intelligence
-
批准号:RGPIN-2017-06650
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$3.64万
-
财政年份:2017
-
负责人:Debbabi, Mourad
-
依托单位:
Fingerprinting and Big Data Security Analytics for the Scalable Generation of Cyber Threat Intelligence
-
批准号:DGDND-2017-00016
-
项目类别:DND/NSERC Discovery Grant Supplement
-
资助金额:$2.91万
-
财政年份:2017
-
负责人:Debbabi, Mourad
-
依托单位:
Advanced Manufacturing (an academia-industry networking event)
-
批准号:494546-2016
-
项目类别:Connect Grants Level 2
-
资助金额:$0.44万
-
财政年份:2016
-
负责人:Debbabi, Mourad
-
依托单位:
NSERC/Hydro-Québec/Thales Industrial Research Chair in Smart Grid Security: Detection, Prevention, Mitigation and Recovery from Cyber-Physical Attacks
-
批准号:501621-2015
-
项目类别:Industrial Research Chairs
-
资助金额:$10.93万
-
财政年份:2016
-
负责人:Debbabi, Mourad
-
依托单位:
Medical Technologies
-
批准号:488782-2015
-
项目类别:Regional Office Discretionary Funds
-
资助金额:$0.22万
-
财政年份:2015
-
负责人:Debbabi, Mourad
-
依托单位:
Training - Building Partnerships
-
批准号:486129-2015
-
项目类别:Regional Office Discretionary Funds
-
资助金额:$0.28万
-
财政年份:2015
-
负责人:Debbabi, Mourad
-
依托单位:
Software Fingerprinting for Automated Malicious Code Analysis
-
批准号:444877-2012
-
项目类别:Department of National Defence / NSERC Research Partnership
-
资助金额:$10.9万
-
财政年份:2015
-
负责人:Debbabi, Mourad
-
依托单位:
Aspect-Oriented Security Hardening of Design Models
-
批准号:183938-2012
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.48万
-
财政年份:2015
-
负责人:Debbabi, Mourad
-
依托单位:
国内基金
海外基金
炭包覆纳米晶的"Oriented Attachment"生长及其多维结构构筑
-
批准号:51572015
-
项目类别:面上项目
-
资助金额:64.0万元
-
批准年份:2015
-
负责人:周继升
-
依托单位: