Incorporating database systems into a secure software development methodology

被引:2
|
作者
Fernandez, Eduardo B. [1 ]
Jurjens, Jan [2 ]
Yoshioka, Nobukazu [3 ]
Washizaki, Hironori [4 ]
机构
[1] Florida Atlantic Univ, Dept Comp Sci, Boca Raton, FL 33431 USA
[2] Open Univ, Dept Comp, Milton Keynes, Bucks MK7 8 GB, England
[3] Natl Inst Informat, GRACE Ctr, Tokyo, Japan
[4] Waseda Univ, Tokyo 169, Japan
关键词
D O I
10.1109/DEXA.2008.100
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
We have proposed in the past three separate methodologies for secure software development. We have found that they have many common and complementary aspects and we proposed a combination of them that appears as a good approach to secure software development. The combined methodology applies security at all stages, considers the architectural levels of the system, applies security policies through the use of patterns, and formalizes some portions of the design. We have studied in some detail how to elicit and describe security requirements, how to reflect these requirements in the conceptual model, how to estimate some performance aspects, how to formalize some aspects such as communication protocols, and how to map the conceptual requirements into design artifacts. A design aspect which we have not studied is the incorporation of databases as part of the secure architecture. The database system is a fundamental aspect for security because it stores the persistent information, which constitutes most of the information assets of the institution. We present here some ideas on how to make sure that the database system has the same level of security than the rest of the secure application.
引用
收藏
页码:310 / +
页数:3
相关论文
共 50 条
  • [1] Towards incorporating discrete-event systems in secure software development
    Whittaker, S. -J.
    Zulkernine, M.
    Rudie, K.
    ARES 2008: PROCEEDINGS OF THE THIRD INTERNATIONAL CONFERENCE ON AVAILABILITY, SECURITY AND RELIABILITY, 2008, : 1188 - +
  • [2] Adaption of a Secure Software Development Methodology for Secure Engineering Design
    Von Solms, Sune
    Futcher, Lynn A.
    IEEE ACCESS, 2020, 8 : 125630 - 125637
  • [3] Towards a Methodology for the Development of Secure Cryptographic Software
    Braga, Alexandre
    Dahab, Ricardo
    PROCEEDINGS OF 2016 INTERNATIONAL CONFERENCE ON SOFTWARE SECURITY AND ASSURANCE (ICSSA), 2016, : 25 - 30
  • [4] Secure software development and testing: A model-based methodology
    Casola, Valentina
    De Benedictis, Alessandra
    Mazzocca, Carlo
    Orbinato, Vittorio
    COMPUTERS & SECURITY, 2024, 137
  • [5] Security Considerations for the Development of Secure Software Systems
    Ruggieri, Maxwell
    Hsu, Tzu-Tang
    Ali, Md Liakat
    2019 IEEE 10TH ANNUAL UBIQUITOUS COMPUTING, ELECTRONICS & MOBILE COMMUNICATION CONFERENCE (UEMCON), 2019, : 1187 - 1193
  • [6] A Secure Software Design Methodology
    Goel, Rajat
    Govil, Mahesh Chandra
    Singh, Girdhari
    2016 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATIONS AND INFORMATICS (ICACCI), 2016, : 2484 - 2488
  • [7] A methodology for secure software design
    Fernandez, EB
    SERP'04: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING RESEARCH AND PRACTICE, VOLS 1 AND 2, 2004, : 130 - 136
  • [8] A New Methodology for the Development of Secure and Paranoid Operating Systems
    Mateus-Coelho, Nuno
    INTERNATIONAL CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS / INTERNATIONAL CONFERENCE ON PROJECT MANAGEMENT / INTERNATIONAL CONFERENCE ON HEALTH AND SOCIAL CARE INFORMATION SYSTEMS AND TECHNOLOGIES 2020 (CENTERIS/PROJMAN/HCIST 2020), 2021, 181 : 1207 - 1215
  • [9] Applying software development methodology to developing help systems
    Nurczyk, SV
    45TH ANNUAL CONFERENCE ON IMAGINATION, INNOVATION AND COMMUNICATION, 1998, : 426 - 428
  • [10] Supporting the development of adaptable and secure software systems: An NFR approach
    Subramanian, N
    Chung, L
    SERP '05: Proceedings of the 2005 International Conference on Software Engineering Research and Practice, Vols 1 and 2, 2005, : 108 - 114