DocumentCode
1991374
Title
A Systematic Review of Model-Driven Security
Author
Nguyen, P.H. ; Klein, John ; Le Traon, Yves ; Kramer, Max E.
Author_Institution
Interdiscipl. Centre for Security, Univ. of Luxembourg, Luxembourg, Luxembourg
Volume
1
fYear
2013
fDate
2-5 Dec. 2013
Firstpage
432
Lastpage
441
Abstract
To face continuously growing security threats and requirements, sound methodologies for constructing secure systems are required. In this context, Model-Driven Security (MDS) has emerged since more than a decade ago as a specialized Model-Driven Engineering approach for supporting the development of secure systems. MDS aims at improving the productivity of the development process and quality of the resulting secure systems, with models as the main artifact. This paper presents how we systematically examined existing published work in MDS and its results. The systematic review process, which is based on a formally designed review protocol, allowed us to identify, classify, and evaluate different MDS approaches. To be more specific, from thousands of relevant papers found, a final set of the most relevant MDS publications has been identified, strictly selected, and reviewed. We present a taxonomy for MDS, which is used to synthesize data in order to classify and evaluate the selected MDS approaches. The results draw a wide picture of existing MDS research showing the current status of the key aspects in MDS as well as the identified most relevant MDS approaches. We discuss the main limitations of the existing MDS approaches and suggest some potential research directions based on these insights.
Keywords
security of data; MDS; MDS publications; formally designed review protocol; model-driven engineering approach; model-driven security; secure systems; security threats; Business; Data mining; Data models; Protocols; Security; Taxonomy; Unified modeling language; model; model transformations; model-driven; model-driven security; security; survey; systematic review;
fLanguage
English
Publisher
ieee
Conference_Titel
Software Engineering Conference (APSEC), 2013 20th Asia-Pacific
Conference_Location
Bangkok
ISSN
1530-1362
Print_ISBN
978-1-4799-2143-0
Type
conf
DOI
10.1109/APSEC.2013.64
Filename
6805435
Link To Document