Goal-Oriented Security Trade-Off Modeling and Analysis with Knowledge Support
نویسنده
چکیده
In designing software systems, security is typically only one design objective among many, which may compete with other objectives such as privacy and usability. Too often, security mechanisms are adopted without explicit recognition of competing design objectives and their origins in stakeholder interests. Ultimately, security is about balancing the trade-offs among the competing goals of multiple actors. However, software developers and designers are not security or privacy specialists, thus a major obstacle towards secure systems development is the lack of an easy-to-use body of knowledge for making trade-offs and decisions. This PhD research focuses on a goal-oriented approach for modeling and analyzing security trade-offs and incorporating them into the requirements analysis and architecture design. Goal orientation is also used to structure knowledge to assist designers in making security trade-offs.
منابع مشابه
Modeling and analysis of security trade-offs - A goal oriented approach
In designing software systems, security is typically only one design objective among many. It may compete with other objectives such as functionality, usability, and performance. Too often, security mechanisms such as firewalls, access control, or encryption are adopted without explicit recognition of competing design objectives and their origins in stakeholders’ interests. Recently, there is i...
متن کاملA Goal Oriented Approach for Modeling and Analyzing Security Trade-Offs with Knowledge Support By
In designing software systems, security is typically only one design objective among many. It may compete with other objectives such as functionality, usability, and performance. Too often, security mechanisms such as firewalls, access control, or encryption are adopted without explicit recognition of competing design objectives and their origins in stakeholder interests. Recently, there is inc...
متن کاملA Goal Oriented Approach for Modeling and Analyzing Security Trade-Offs
In designing software systems, security is typically only one design objective among many. It may compete with other objectives such as functionality, usability, and performance. Too often, security mechanisms such as firewalls, access control, or encryption are adopted without explicit recognition of competing design objectives and their origins in stakeholder interests. Recently, there is inc...
متن کاملDecision Support for Choice of Security Solution: The Aspect-Oriented Risk Driven Development (AORDD)Framework
Security critical systems development needs to integrate both project and product risks assessment into the development. Such systems need to balance time to market constraints, cost demands, functional requirement, as well as security requirements. This advocate the use of techniques that support costeffective and risk-driven development. The aspect-oriented risk-driven development (AORDD) fra...
متن کاملThreat Analysis in Goal-Oriented Security Requirements Modelling
Goal and threat modelling are important activities of security requirements engineering: goals express why a system is needed, while threats motivate the need for security. Unfortunately, existing approaches mostly consider goals and threats separately, and thus neglect the mutual influence between them. In this paper, we address this deficiency by proposing an approach that extends goal modell...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2008