DocumentCode
2080464
Title
A resource-based approach to formalize use case specification for web applications
Author
Xu, Weifeng ; Deng, Lin ; Liu, Yunkai
Author_Institution
Dept. of Comput. & Inf. Sci., Gannon Univ., Erie, PA, USA
Volume
2
fYear
2010
fDate
10-12 Dec. 2010
Firstpage
1072
Lastpage
1076
Abstract
Web applications under attack may perform undesirable behaviors against their use case specification. These attacks exploit web vulnerabilities which are usually considered as consequences of abusing web resources. The paper proposes a resource-based approach to formalize use case specification for web applications. The goal of the research is to identify and organize web resources, and to integrate web resources into use cases in a structured way. First, we filter web resource information based on the lexical analysis of the original use case specification. Then, we identify hidden web resources that are not listed in the event flow but required during the realization of the event. After that, we organize these web resources into a web resource tree. Finally, the formalized use case specification is constructed into a tree structure along with a defined event flow grammar. The resource-based use case specification enables security analysts to analyze the web vulnerabilities in terms of the resources required by each event. It is helpful to elicit security requirements.
Keywords
Internet; formal specification; security of data; tree data structures; Web applications; Web vulnerabilities; event flow grammar; tree structure; use case specification formalization; Pragmatics; event flow tree; requirement engineering; security requirements; use case formalization; web resources categorization;
fLanguage
English
Publisher
ieee
Conference_Titel
Progress in Informatics and Computing (PIC), 2010 IEEE International Conference on
Conference_Location
Shanghai
Print_ISBN
978-1-4244-6788-4
Type
conf
DOI
10.1109/PIC.2010.5688003
Filename
5688003
Link To Document