DocumentCode :
2571477
Title :
A Pattern-Based General Security Framework: An eBusiness Case Study
Author :
Benameur, Azzedine ; Fenet, Serge ; Saidane, Ayda ; Sinha, Smriti Kumar
Author_Institution :
SAP Res., SAP Labs. France, Sophia Antipolis, France
fYear :
2009
fDate :
25-27 June 2009
Firstpage :
339
Lastpage :
346
Abstract :
Security and domain specific regulations are critical for any organization. Unfortunately, achieving these prerequisites in a socio-technical environment is a difficult task. For example, let us consider the aspect of computer security: neither software developers nor regulatory authorities are security experts. Therefore, it is important that security experts´ knowledge is captured and made available to software developers. Security patterns are a suitable prescription to capture experts´ solutions to commonly recurring security problems. In this paper, we present the application of a general framework, based on security patterns, used to develop secure applications. It covers the entire process of solution development: defining organizational security requirements using SECURE TROPOS, formalizing the pattern using SI*, implementing the pattern, integrating it into the final application, and monitoring the runtime. All these phases are discussed and illustrated with an eBusiness case study: the loan origination process.
Keywords :
bank data processing; electronic commerce; object-oriented programming; security of data; SI* methodology; banking domain; e-business; loan origination process; organizational security requirement; pattern-based general security framework; secure tropos; socio-technical environment; software developer; Application software; Banking; Collaboration; Computer security; High performance computing; Monitoring; National security; Privacy; Risk management; Runtime; Ebusiness; SOA; Security Engineering; Security Patterns;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
High Performance Computing and Communications, 2009. HPCC '09. 11th IEEE International Conference on
Conference_Location :
Seoul
Print_ISBN :
978-1-4244-4600-1
Electronic_ISBN :
978-0-7695-3738-2
Type :
conf
DOI :
10.1109/HPCC.2009.93
Filename :
5167012
Link To Document :
بازگشت