Modeling Security Concerns in Service-Oriented Architecture
نویسنده
چکیده
Many enterprises are implementing service-oriented architecture (SOA) using Web services, and are designing those services according to the principles of Model Driven Architecture (MDA). Because the UML used to express MDA lacks model elements for indicating the security needs of business processes, system architects are forced either to ignore security concerns in their models, or to indicate their intentions in ways that are implementation-specific. This paper proposes a candidate profile for UML that presents security-related intent elements as stereotypes that business users and software architects can apply to UML elements when working with business stakeholders to capture business requirements. Using a profile such as the one proposed here would allow architects to specify the business intent of security in their designs without violating the MDA prohibition against implementation-specific details in high-level, behavioral models.
منابع مشابه
An Autonomic Service Oriented Architecture in Computational Engineering Framework
Service Oriented Architecture (SOA) technology enables composition of large and complex computational units out of the available atomic services. Implementation of SOA brings about challenges which include service discovery, service interaction, service composition, robustness, quality of service, security, etc. These challenges are mainly due to the dynamic nature of SOA. SOAmay often need to ...
متن کاملAn Autonomic Service Oriented Architecture in Computational Engineering Framework
Service Oriented Architecture (SOA) technology enables composition of large and complex computational units out of the available atomic services. Implementation of SOA brings about challenges which include service discovery, service interaction, service composition, robustness, quality of service, security, etc. These challenges are mainly due to the dynamic nature of SOA. SOAmay often need to ...
متن کاملاز پیاده سازی معماری سرویس گرا تا چابکی سازمان با رویکرد مدلسازی پویایی سیستم
SOA is type of architecture that used service to simplify integration activities and use the components for reusable. Companies to survive in the dynamic environment needed to strengthen their organizations through information systems and service-oriented architecture is a way for the integration and effectiveness of the use of information systems and achieve organizational agility. In this pap...
متن کاملAn Aspect-Oriented Approach to Early Design Modeling
Developers of modern software systems are often required to build software that address security, fault-tolerance, and other dependability concerns. A decision to address a dependability concern in a particular manner can make it difficult or impossible to address other concerns in software. Proper attention to balancing key dependability and other concerns in the early phases of development ca...
متن کاملCross-organizational Service Security – Solutions for Attack Modeling and Defense
Security is an important aspect of Service-oriented Architectures (SOAs), enabling the service-based integration of partner IT systems across organizational boundaries, i. e., in the Internet of Services. Current trends in SOA security, e. g., reducing it to Web service security, do not take into account SOA-specific threats, vulnerabilities, and attacks. In this paper, measures to support the ...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2005