• DocumentCode
    1732906
  • Title

    A method for modeling and analyzing the security attributes of service-oriented software system

  • Author

    Li, Liu ; Chunlei, Wang ; Liang, Ming

  • Author_Institution
    Sci. & Technol. on Inf. Syst. Security Lab., Beijing, China
  • Volume
    2
  • fYear
    2011
  • Firstpage
    625
  • Lastpage
    629
  • Abstract
    In Service Oriented Architecture (SOA), software is implemented through a series of services and the business processes composed of services which introduce potential security problems. These security problems appeared in SOA software applications usually lead information systems and their business processes to risks. Similar to traditional quality of service (QoS) attributes such as reliability and robustness, security is one of the most important attributes of software system. In this paper, the method for modeling and analyzing the security attributes of SOA software system is investigated. Firstly, the service oriented computing model for security analysis is constructed, which characterizes service computing paradigm and related security attributes, and can be used for establishing service oriented software security metric system. Secondly, the service attack path is analyzed based upon the service oriented computing model. Finally, the effectiveness of the model and the analysis method is validated through case studies.
  • Keywords
    information systems; security of data; service-oriented architecture; software metrics; software reliability; SOA software applications; information systems; quality of service attributes; reliability; robustness; security attributes; security problems; service attack path; service computing paradigm; service oriented architecture; service oriented software security metric system; Analytical models; Computational modeling; Information systems; Irrigation; Laboratories; Security; Software; security analysis; security model; service oriented architecture; software security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Science and Network Technology (ICCSNT), 2011 International Conference on
  • Conference_Location
    Harbin
  • Print_ISBN
    978-1-4577-1586-0
  • Type

    conf

  • DOI
    10.1109/ICCSNT.2011.6182044
  • Filename
    6182044