From Goal-Driven Security Requirements Engineering to Secure Design

被引:35
|
作者
Mouratidis, Haralambos [1 ]
Jurjens, Jan [2 ,3 ]
机构
[1] Univ E London, Sch Comp Informat Technol & Engn, London E16 2RD, England
[2] TU Dortmund, Dortmund, Germany
[3] Fraunhofer ISST, Dortmund, Germany
关键词
FRAMEWORK;
D O I
10.1002/int.20432
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Security of intelligent software systems is an important area of research. Although security is traditionally considered a technical issue; security is, in fact, a two-dimensional problem, which involves technical as well as social challenges. Goal-driven requirements engineering (GDRE) has been proposed in the literature as a suitable paradigm for the analysis of security issues and elicitation of security requirements at both the social and technical level. Nevertheless, there is lack of approaches, which would support the successful transformation of the elicited, using GDRE approaches, security requirements to design. This paper presents work that fills this gap. The presented approach, which is based on the integration of a goal-driven security requirements engineering (GDSRE) methodology and a model-based security engineering (MBSE) method, has some important features: (1) It provides a structured process to translate the results of the GDSRE method to a design, which satisfies these requirements; (2) it allows the simultaneous elicitation and analysis of the security requirements and the functional requirements of the system; (3) it allows consideration of both the social and the technical dimensions of the system's security; (4) it guides software engineers toward a design that is amenable to formal verification with the aid of automated tools. We demonstrate the applicability of the proposed approach at the hand of an application to the electronic purse standard common electronic purse specifications (released by Visa International and others). (c) 2010 Wiley Periodicals, Inc.
引用
收藏
页码:813 / 840
页数:28
相关论文
共 50 条
  • [21] Goal-driven modeling
    Bock, Conrad
    JOOP - Journal of Object-Oriented Programming, 2000, 13 (05): : 48 - 56
  • [22] GRAIL/KAOS: An environment for goal-driven requirements analysis, integration and layout
    Darimont, R
    Delor, E
    Massonet, P
    vanLamsweerde, A
    RE '97 - PROCEEDINGS OF THE THIRD IEEE INTERNATIONAL SYMPOSIUM ON REQUIREMENTS ENGINEERING, 1997, : 140 - 140
  • [23] Goal-driven requirements analysis for hypermedia-intensive Web applications
    Davide Bolchini
    Paolo Paolini
    Requirements Engineering, 2004, 9 : 85 - 103
  • [24] Essence-Based, Goal-Driven Adaptive Software Engineering
    Park, June Sung
    2015 IEEE/ACM 4TH SEMAT WORKSHOP ON A GENERAL THEORY OF SOFTWARE ENGINEERING (GTSE), 2015, : 33 - 38
  • [25] Goal-driven requirements analysis for hypermedia-intensive Web applications
    Bolchini, D
    Paolini, P
    REQUIREMENTS ENGINEERING, 2004, 9 (02) : 85 - 103
  • [26] Pragmatic Requirements for Adaptive Systems: A Goal-Driven Modeling and Analysis Approach
    Guimaraes, Felipe Pontes
    Rodrigues, Genaina Nunes
    Batista, Daniel Macedo
    Ali, Raian
    CONCEPTUAL MODELING, ER 2015, 2015, 9381 : 50 - 64
  • [27] A Goal-Driven Approach to Modeling Security Concerns in Network Management System
    Wu, Chia-Ling
    49TH ANNUAL IEEE INTERNATIONAL CARNAHAN CONFERENCE ON SECURITY TECHNOLOGY (ICCST), 2015, : 123 - 129
  • [28] Goal-Driven Atari Environment
    Kim, Myeong Hyeon
    Kim, Dongjae
    Jo, Eunsong
    Lee, Sang Wan
    10TH INTERNATIONAL WINTER CONFERENCE ON BRAIN-COMPUTER INTERFACE (BCI2022), 2022,
  • [29] GOAL-DRIVEN LOTOS EXECUTION
    BRINKSMA, E
    EERTINK, H
    PROTOCOL SPECIFICATION, TESTING AND VERIFICATION, XIII, 1993, 16 : 45 - 60
  • [30] Habitual Behavior Is Goal-Driven
    Kruglanski, Arie W.
    Szumowska, Ewa
    PERSPECTIVES ON PSYCHOLOGICAL SCIENCE, 2020, 15 (05) : 1256 - 1271