• DocumentCode
    1991374
  • Title

    A Systematic Review of Model-Driven Security

  • Author

    Nguyen, P.H. ; Klein, John ; Le Traon, Yves ; Kramer, Max E.

  • Author_Institution
    Interdiscipl. Centre for Security, Univ. of Luxembourg, Luxembourg, Luxembourg
  • Volume
    1
  • fYear
    2013
  • fDate
    2-5 Dec. 2013
  • Firstpage
    432
  • Lastpage
    441
  • Abstract
    To face continuously growing security threats and requirements, sound methodologies for constructing secure systems are required. In this context, Model-Driven Security (MDS) has emerged since more than a decade ago as a specialized Model-Driven Engineering approach for supporting the development of secure systems. MDS aims at improving the productivity of the development process and quality of the resulting secure systems, with models as the main artifact. This paper presents how we systematically examined existing published work in MDS and its results. The systematic review process, which is based on a formally designed review protocol, allowed us to identify, classify, and evaluate different MDS approaches. To be more specific, from thousands of relevant papers found, a final set of the most relevant MDS publications has been identified, strictly selected, and reviewed. We present a taxonomy for MDS, which is used to synthesize data in order to classify and evaluate the selected MDS approaches. The results draw a wide picture of existing MDS research showing the current status of the key aspects in MDS as well as the identified most relevant MDS approaches. We discuss the main limitations of the existing MDS approaches and suggest some potential research directions based on these insights.
  • Keywords
    security of data; MDS; MDS publications; formally designed review protocol; model-driven engineering approach; model-driven security; secure systems; security threats; Business; Data mining; Data models; Protocols; Security; Taxonomy; Unified modeling language; model; model transformations; model-driven; model-driven security; security; survey; systematic review;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Software Engineering Conference (APSEC), 2013 20th Asia-Pacific
  • Conference_Location
    Bangkok
  • ISSN
    1530-1362
  • Print_ISBN
    978-1-4799-2143-0
  • Type

    conf

  • DOI
    10.1109/APSEC.2013.64
  • Filename
    6805435