Security Modeling of SOA System Using Security Intent DSL

Author(s):  
Muhammad Qaiser Saleem ◽  
Jafreezal Jaafar ◽  
Mohd Fadzil Hassan
Keyword(s):  
Author(s):  
Ayda Saidane ◽  
Nicolas Guelfi

The quality of software systems depends strongly on their architecture. For this reason, taking into account non-functional requirements at architecture level is crucial for the success of the software development process. Early architecture model validation facilitates the detection and correction of design errors. In this research, the authors are interested in security critical systems, which require a reliable validation process. So far, they are missing security-testing approaches providing an appropriate compromise between software quality and development cost while satisfying certification and audit procedures requirements through automated and documented validation activities. In this chapter, the authors propose a novel test-driven and architecture model-based security engineering approach for resilient systems. It consists of a test-driven security modeling framework and a test based validation approach. The assessment of the security requirement satisfaction is based on the test traces analysis. Throughout this study, the authors illustrate the approach using a client server architecture case study.


2014 ◽  
pp. 2072-2098
Author(s):  
Ayda Saidane ◽  
Nicolas Guelfi

The quality of software systems depends strongly on their architecture. For this reason, taking into account non-functional requirements at architecture level is crucial for the success of the software development process. Early architecture model validation facilitates the detection and correction of design errors. In this research, the authors are interested in security critical systems, which require a reliable validation process. So far, they are missing security-testing approaches providing an appropriate compromise between software quality and development cost while satisfying certification and audit procedures requirements through automated and documented validation activities. In this chapter, the authors propose a novel test-driven and architecture model-based security engineering approach for resilient systems. It consists of a test-driven security modeling framework and a test based validation approach. The assessment of the security requirement satisfaction is based on the test traces analysis. Throughout this study, the authors illustrate the approach using a client server architecture case study.


Author(s):  
Matt Campo ◽  
Michael Greenberg ◽  
Henry Mayer ◽  
Karen Lowrie

The National Transportation Security Center of Excellence (NTSCOE) was established in August 2007 to develop new approaches to defend, protect, and increase the resilience of the nation's multi-modal transportation infrastructure, and to create education and training programs for transportation security. The Center for Transportation Safety, Security, and Risk (CTSSR) at Rutgers University, an NTSCOE institution, developed models that address multi-modal resilience of freight and transit transportation networks. Data collection processes for each project presented significant hurdles for the research team in developing credible and accurate modeling tools. For any given data need, the potential exists for data gaps, collection, and processing errors, publication and use restrictions, and the need to obtain the most timely information. These challenges must be foreseen by researchers and practitioners in order to better accommodate potential restrictions on both data collection and dissemination while still providing users with a tool that improves decision making.


Sign in / Sign up

Export Citation Format

Share Document