Goal-Oriented Security Trade-Off Modeling and Analysis with Knowledge Support

نویسنده

  • Golnaz Elahi
چکیده

In designing software systems, security is typically only one design objective among many, which may compete with other objectives such as privacy and usability. Too often, security mechanisms are adopted without explicit recognition of competing design objectives and their origins in stakeholder interests. Ultimately, security is about balancing the trade-offs among the competing goals of multiple actors. However, software developers and designers are not security or privacy specialists, thus a major obstacle towards secure systems development is the lack of an easy-to-use body of knowledge for making trade-offs and decisions. This PhD research focuses on a goal-oriented approach for modeling and analyzing security trade-offs and incorporating them into the requirements analysis and architecture design. Goal orientation is also used to structure knowledge to assist designers in making security trade-offs.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Modeling and analysis of security trade-offs - A goal oriented approach

In designing software systems, security is typically only one design objective among many. It may compete with other objectives such as functionality, usability, and performance. Too often, security mechanisms such as firewalls, access control, or encryption are adopted without explicit recognition of competing design objectives and their origins in stakeholders’ interests. Recently, there is i...

متن کامل

A Goal Oriented Approach for Modeling and Analyzing Security Trade-Offs with Knowledge Support By

In designing software systems, security is typically only one design objective among many. It may compete with other objectives such as functionality, usability, and performance. Too often, security mechanisms such as firewalls, access control, or encryption are adopted without explicit recognition of competing design objectives and their origins in stakeholder interests. Recently, there is inc...

متن کامل

A Goal Oriented Approach for Modeling and Analyzing Security Trade-Offs

In designing software systems, security is typically only one design objective among many. It may compete with other objectives such as functionality, usability, and performance. Too often, security mechanisms such as firewalls, access control, or encryption are adopted without explicit recognition of competing design objectives and their origins in stakeholder interests. Recently, there is inc...

متن کامل

Decision Support for Choice of Security Solution: The Aspect-Oriented Risk Driven Development (AORDD)Framework

Security critical systems development needs to integrate both project and product risks assessment into the development. Such systems need to balance time to market constraints, cost demands, functional requirement, as well as security requirements. This advocate the use of techniques that support costeffective and risk-driven development. The aspect-oriented risk-driven development (AORDD) fra...

متن کامل

Threat Analysis in Goal-Oriented Security Requirements Modelling

Goal and threat modelling are important activities of security requirements engineering: goals express why a system is needed, while threats motivate the need for security. Unfortunately, existing approaches mostly consider goals and threats separately, and thus neglect the mutual influence between them. In this paper, we address this deficiency by proposing an approach that extends goal modell...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2008