DocumentCode :
2703975
Title :
A Service-Oriented Framework for Quantitative Security Analysis of Software Architectures
Author :
Liu, Yanguo ; Traore, Issa ; Hoole, Alexander M.
Author_Institution :
Dept. of Electr. & Comput. Eng., Univ. of Victoria, Victoria, BC
fYear :
2008
fDate :
9-12 Dec. 2008
Firstpage :
1231
Lastpage :
1238
Abstract :
Software systems today often run in malicious environments in which attacks or intrusions are quite common. This situation has brought security concerns into the development of software systems. Generally, software services are expected not only to satisfy functional requirements but also to be resistant to malicious attacks. Software attackability is defined as the likelihood that an attack on a software system will succeed. In this paper, we present a service-oriented framework to analyze attackability of software systems. More specifically, we propose a User System Interaction Effect (USIE) model that can be used systematically to derive and analyze security concerns from service-oriented software architectures. Many aspects of the model derivation and analysis can be automated, which limit the amount of user involvement, and thereby reduce the subjectivity underlying typical security risk analysis process. The model can be used as a foundation for quantitative analysis of software services from different security perspectives.
Keywords :
Web services; human computer interaction; risk analysis; security of data; software architecture; software quality; malicious software attackability; quantitative security analysis; security risk analysis process; service-oriented software architecture; software quality attribute; software system; user system interaction effect model; Computer architecture; Computer crime; Computer security; Programming; Risk analysis; Service oriented architecture; Software architecture; Software measurement; Software quality; Software systems; Architecture Analysis; Security Engineering; Service-oriented Development; Software Attackability; Software Metrics;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Asia-Pacific Services Computing Conference, 2008. APSCC '08. IEEE
Conference_Location :
Yilan
Print_ISBN :
978-0-7695-3473-2
Electronic_ISBN :
978-0-7695-3473-2
Type :
conf
DOI :
10.1109/APSCC.2008.17
Filename :
4780848
Link To Document :
بازگشت