DocumentCode :
3549530
Title :
Cost-benefit trade-off analysis using BBN for aspect-oriented risk-driven development
Author :
Houmb, Siv Hilde ; Georg, Geri ; France, Robert ; Bieman, James ; Jürjens, Jan
Author_Institution :
Dept. of Comput. Sci., Norwegian Univ. of Sci. & Technol., Trondheim, Norway
fYear :
2005
fDate :
16-20 June 2005
Firstpage :
195
Lastpage :
204
Abstract :
Security critical systems must perform at the required security level, make effective use of available resources, and meet end-users expectations. Balancing these needs, and at the same time fulfilling budget and time-to-market constraints, requires developers to design and evaluate alternative security treatment strategies. In this paper, the authors presented a development framework that utilizes Bayesian belief networks (BBN) and aspect-oriented modeling (AOM) for a cost-benefit trade-off analysis of treatment strategies. AOM allows developers to model pervasive security treatments separately from other system functionality. This eases the trade-off by making it possible to swap treatment strategies in and out when computing return on security investments (RoSI). The trade-off analysis is implemented using BBN, and RoSI is computed by estimating a set of variables describing properties of a treatment strategy. RoSI for each treatment strategy is then used as input to choice of design.
Keywords :
belief networks; cost-benefit analysis; formal specification; object-oriented programming; risk analysis; security of data; Bayesian belief networks; RoSI; aspect-oriented modeling; aspect-oriented risk-driven development; cost-benefit trade-off analysis; end-users expectations; pervasive security treatment; return on security investments; security critical systems; system functionality; time-to-market constraints; Bayesian methods; Computer science; Computer security; Data security; Information security; Investments; Risk analysis; Software performance; Topology; Unified modeling language; Aspect-Oriented Modeling (AOM); Bayesian Belief Networks (BBN); Trade-off analysis; and Risk-Driven Development (RDD);
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Engineering of Complex Computer Systems, 2005. ICECCS 2005. Proceedings. 10th IEEE International Conference on
Print_ISBN :
0-7695-2284-X
Type :
conf
DOI :
10.1109/ICECCS.2005.30
Filename :
1467900
Link To Document :
بازگشت