Modeling and Applying Security Patterns Using Contextual Goal Models
نویسندگان
چکیده
Security patterns have been proposed to help analysts with little security knowledge to tackle repetitive security design tasks. Although advanced research in this field has produced an impressive collection of patterns, they are not well integrated with security requirements analysis and not easy to apply. Goal-oriented modeling languages have been proposed as an effective way to capture requirements, including security requirements, for socio-technical systems. In this paper, we argue that modeling and analyzing security patterns in contextual goal models can facilitate their applications and magnify their influences in system security design. Particularly, we present a mapping between security patterns and contextual goal models, and provide practical guidelines for transforming textual security patterns into the goal models. In addition, we propose a systematic process for applying security patterns, and discuss how it can be combined with existing security requirements analysis approaches.
منابع مشابه
Integrating Security Patterns with Security Requirements Analysis Using Contextual Goal Models
Security patterns capture proven security knowledge to help analysts tackle security problems. Although advanced research in this field has produced an impressive collection of patterns, they are not widely applied in practice. In parallel, Requirements Engineering has been increasing focusing on security-specific issues, arguing for an upfront treatment of security in system design. However, t...
متن کاملModel Contextual Variability for Agents Using Goals and Commitments
Goal models have been extensively utilized in requirements engineering as they provide an expressive and qualitative way to represent requirements, while recent extensions related to contextual variability have further increased the expressiveness of the models. In addition to their application in requirements engineering however, goal models have been also proposed in the literature as a forma...
متن کاملAutomatic Contextual Pattern Modeling
A contextual pattern consists of many pattern primitives among which various contextual relations are defined. This work proposes a computational model for automatically modeling and extracting contextual patterns from multiple samples. Those samples represent the contextual patterns observed under various conditions and backgrounds. Attributed relational graph (ARG) is chosen as the informatio...
متن کاملPattern Based Security Requirement Derivation with Security Risk-aware Secure Tropos
Information systems (IS’s) support a multitude of functions vital to the modern society. IS’s carry an ever increasing volume of data and information, including personal pictures, health data or financial transactions. Continuously increasing rates of cyber-attacks have led to the subsequent need to rapidly develop secure IS. To develop secure IS’s, security goals need to be identified and fulf...
متن کاملThe Analysis of Bayesian Probit Regression of Binary and Polychotomous Response Data
The goal of this study is to introduce a statistical method regarding the analysis of specific latent data for regression analysis of the discrete data and to build a relation between a probit regression model (related to the discrete response) and normal linear regression model (related to the latent data of continuous response). This method provides precise inferences on binary and multinomia...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2014