• DocumentCode
    2571477
  • Title

    A Pattern-Based General Security Framework: An eBusiness Case Study

  • Author

    Benameur, Azzedine ; Fenet, Serge ; Saidane, Ayda ; Sinha, Smriti Kumar

  • Author_Institution
    SAP Res., SAP Labs. France, Sophia Antipolis, France
  • fYear
    2009
  • fDate
    25-27 June 2009
  • Firstpage
    339
  • Lastpage
    346
  • Abstract
    Security and domain specific regulations are critical for any organization. Unfortunately, achieving these prerequisites in a socio-technical environment is a difficult task. For example, let us consider the aspect of computer security: neither software developers nor regulatory authorities are security experts. Therefore, it is important that security experts´ knowledge is captured and made available to software developers. Security patterns are a suitable prescription to capture experts´ solutions to commonly recurring security problems. In this paper, we present the application of a general framework, based on security patterns, used to develop secure applications. It covers the entire process of solution development: defining organizational security requirements using SECURE TROPOS, formalizing the pattern using SI*, implementing the pattern, integrating it into the final application, and monitoring the runtime. All these phases are discussed and illustrated with an eBusiness case study: the loan origination process.
  • Keywords
    bank data processing; electronic commerce; object-oriented programming; security of data; SI* methodology; banking domain; e-business; loan origination process; organizational security requirement; pattern-based general security framework; secure tropos; socio-technical environment; software developer; Application software; Banking; Collaboration; Computer security; High performance computing; Monitoring; National security; Privacy; Risk management; Runtime; Ebusiness; SOA; Security Engineering; Security Patterns;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    High Performance Computing and Communications, 2009. HPCC '09. 11th IEEE International Conference on
  • Conference_Location
    Seoul
  • Print_ISBN
    978-1-4244-4600-1
  • Electronic_ISBN
    978-0-7695-3738-2
  • Type

    conf

  • DOI
    10.1109/HPCC.2009.93
  • Filename
    5167012