DocumentCode :
2779981
Title :
Security Design Based on Social Modeling
Author :
Liu, Lin ; Yu, Eric ; Mylopoulos, John
Author_Institution :
Sch. of Software, Tsinghua Univ., Beijing
Volume :
2
fYear :
2006
fDate :
17-21 Sept. 2006
Firstpage :
71
Lastpage :
78
Abstract :
Design for security is extremely complicated due to the unique nature of the issue. It requires a thorough understanding about the social setting of the security system. To obtain such understanding, sensible steps to take include identifying the players involved in the system, recognizing their personal preferences, agenda and power in relation to other players, identifying the assets being protected, the vulnerable points at which the systems may fail when attacked. Equally important is to taking rationale steps to predict most likely attackers, knowing their possible motivations, and capabilities enabled by latest the technologies and resource occupations. Only based on integrated analysis on both sides, rationale, informative and efficient tradeoffs on security can be made. Unfortunately, current system development practices treat design decisions on security in an ad-hoc way, often as an afterthought. This paper proposes to use social modeling concepts to analyze the business and organizational context of systems with regard to security. The main concepts used are actor, role, agent and goal, task, and resource dependencies between actors. The approach encompasses several analysis steps on the functional and non-functional requirements in relevance to security, thus integrating security into the system design process from the outset
Keywords :
multi-agent systems; security of data; functional requirements; nonfunctional requirements; resource dependencies; security design; security system; social modeling; Computer science; Computer security; Control systems; Information security; Instruments; Pattern analysis; Power system security; Privacy; Protection; Satellite broadcasting;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Software and Applications Conference, 2006. COMPSAC '06. 30th Annual International
Conference_Location :
Chicago, IL
ISSN :
0730-3157
Print_ISBN :
0-7695-2655-1
Type :
conf
DOI :
10.1109/COMPSAC.2006.159
Filename :
4020144
Link To Document :
بازگشت