Improving software security through an integrated approach

被引:0
|
作者
Gan, Zaobin [1 ]
Wei, Dengwei [1 ]
Varadharajan, Vijay [2 ]
机构
[1] Huazhong Univ Sci & Technol, Wuhan 430074, Peoples R China
[2] Macquarie Univ, Dept Comp, Sydney, NSW 2109, Australia
关键词
system integration; RBAC;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
It has been recognized that the main source of problems with application software security is in most cases that the software is poorly designed and developed with respect to authentication and authorization. Aiming at preventing the security issues in the course of software design and development, this paper presents a framework for integrating a security policy specification with a system function integration. On the basis of the Role-Based Access Control (RBAC) model, this framework moves the responsibility of security through a central authorization management mechanism, Single Sign-On (SSO) access and integration management of security resources. The design can integrate the enterprise's multiple new, developing and existing application systems, and provide end users access these systems as a single system. An application instance of the framework is given in a large-sized enterprise information integrated system as well. The results show that the framework may provide enterprises with uniform and robust enforcement policies to improve the security of sensitive information systems.
引用
收藏
页码:437 / +
页数:2
相关论文
共 50 条
  • [1] Reducing software security risk through an integrated approach
    Gilliam, DP
    Powell, JD
    Kelly, JC
    Bishop, M
    26TH ANNUAL NASA GODDARD SOFTWARE ENGINEERING WORKSHOP, PROCEEDINGS, 2002, : 36 - 42
  • [2] Reducing software security risk through an integrated approach
    Gilliam, DP
    Kelly, JC
    Bishop, M
    IEEE 9TH INTERNATIONAL WORKSHOPS ON ENABLING TECHNOLOGIES: INFRASTRUCTURE FOR COLLABORATIVE ENTERPRISES, PROCEEDINGS, 2000, : 141 - 146
  • [3] An integrated approach to security in software development methodologies
    Raman, Abhay
    Muegge, Steven
    2008 CANADIAN CONFERENCE ON ELECTRICAL AND COMPUTER ENGINEERING, VOLS 1-4, 2008, : 1921 - 1924
  • [4] Managing Software Security Risks through an Integrated Computational
    Alharbi, Abdullah
    Alosaimi, Wael
    Alyami, Hashem
    Nadeem, Mohd
    Faizan, Mohd
    Agrawal, Alka
    Kumar, Rajeev
    Khan, Raees Ahmad
    INTELLIGENT AUTOMATION AND SOFT COMPUTING, 2021, 28 (01): : 179 - 194
  • [5] A Software Approach to Improving Cloud Computing Datacenter Energy Efficiency and Enhancing Security through Botnet Detection
    Dinita, Razvan-Ioan
    Winckles, Adrian
    Wilson, George
    2016 IEEE 14TH INTERNATIONAL CONFERENCE ON INDUSTRIAL INFORMATICS (INDIN), 2016, : 816 - 819
  • [6] Improving software Modeling process through a framework approach
    Paiano, Roberto
    Guido, Anna Lisa
    Pandurino, Andrea
    EDUCATION TRAINING AND INFORMATION COMMUNICATION TECHNOLOGIES ROEDUNET' 05: PROCEEDINGS OF THE 4TH INTERNATIONAL CONFERENCE ROEDUNET ROMANIA, 2005, : 190 - 207
  • [7] Improving system performance through an integrated design approach
    Wits, Wessel W.
    van Houten, Fred J. A. M.
    CIRP ANNALS-MANUFACTURING TECHNOLOGY, 2011, 60 (01) : 187 - 190
  • [8] Improving BOP reliability through an integrated management approach
    20183405719639
    (1) Queiroz Galvao Oleo e Gas, Brazil, 1600, (Offshore Technology Conference):
  • [9] Improving bone health: addressing the burden through an integrated approach
    Bussell, Mary E.
    AGING CLINICAL AND EXPERIMENTAL RESEARCH, 2021, 33 (10) : 2777 - 2786
  • [10] Improving Physical Health outcomes through assertive and integrated approach
    Legha, Gaganpreet Kaur
    INTERNATIONAL JOURNAL OF MENTAL HEALTH NURSING, 2016, 25 : 28 - 28