DocumentCode :
2864918
Title :
Towards an Enhanced Design Level Security: Integrating Attack Trees with Statecharts
Author :
El Ariss, O. ; Wu, Jianfei ; Xu, Dianxiang
Author_Institution :
Dept. of Comput. Sci., North Dakota State Univ., Fargo, ND, USA
fYear :
2011
fDate :
27-29 June 2011
Firstpage :
1
Lastpage :
10
Abstract :
Software security has become more and more critical as we are increasingly depending on the Internet, an untrustworthy computing environment. Software functionality and security are tightly related to each other, vulnerabilities due to design errors, inconsistencies, incompleteness, and missing constraints in system specifications can be wrongly exploited by security attacks. These two concerns, however, are often handled separately. In this paper we present a threat driven approach that improves on the quality of software through the realization of a more secure functional model. The approach introduces systematic transformation rules and integration steps for mapping attack tree representations into lower level dynamic behavior, then integrates this behavior into state chart-based functional models. Through the focus on both the functional and threat behavior, software engineers can introduce, clearly define and understand security concerns as software is designed. To identify vulnerabilities, our approach then applies security analysis and threat identification to the integrated model.
Keywords :
Internet; formal specification; safety-critical software; security of data; software quality; Internet; mapping attack tree representations; software functionality; software quality; software security; statechart-based functional models; system specifications; systematic transformation rules; threat driven approach; threat identification; untrustworthy computing; vulnerabilities; Analytical models; HTML; Logic gates; Security; Semantics; Software; Unified modeling language; Software security; attack trees; software design; statecharts; system modeling; threat modeling;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Secure Software Integration and Reliability Improvement (SSIRI), 2011 Fifth International Conference on
Conference_Location :
Jeju Island
Print_ISBN :
978-1-4577-0780-3
Electronic_ISBN :
978-0-7695-4453-3
Type :
conf
DOI :
10.1109/SSIRI.2011.11
Filename :
5991998
Link To Document :
بازگشت