• Title of article

    A systematic approach to integrate common timed security rules within a TEFSM-based system specification

  • Author/Authors

    Mammar، نويسنده , , Amel and Mallouli، نويسنده , , Wissam and Cavalli، نويسنده , , Ana، نويسنده ,

  • Issue Information
    ماهنامه با شماره پیاپی سال 2012
  • Pages
    12
  • From page
    87
  • To page
    98
  • Abstract
    Context methods are very useful in the software industry and are becoming of paramount importance in practical engineering techniques. They involve the design and modeling of various system aspects expressed usually through different paradigms. These different formalisms make the verification of global developed systems more difficult. ive s paper, we propose to combine two modeling formalisms, in order to express both functional and security timed requirements of a system to obtain all the requirements expressed in a unique formalism. the system behavior is specified according to its functional requirements using Timed Extended Finite State Machine (TEFSM) formalism. Second, this model is augmented by applying a set of dedicated algorithms to integrate timed security requirements specified in Nomad language. This language is adapted to express security properties such as permissions, prohibitions and obligations with time considerations. s oposed algorithms produce a global TEFSM specification of the system that includes both its functional and security timed requirements. sion concluded that it is possible to merge several requirement aspects described with different formalisms into a global specification that can be used for several purposes such as code generation, specification correctness proof, model checking or automatic test generation. In this paper, we applied our approach to a France Telecom Travel service to demonstrate its scalability and feasibility.
  • Keywords
    Nomad language , Timed extended finite state machines , formal methods , Test generation
  • Journal title
    Information and Software Technology
  • Serial Year
    2012
  • Journal title
    Information and Software Technology
  • Record number

    2374752