• DocumentCode
    3145501
  • Title

    Specifying Security Goals of Component Based Systems: An End-User Perspective

  • Author

    Khan, Khaled M. ; Han, Jun

  • Author_Institution
    Qatar Univ., Doha
  • fYear
    2008
  • fDate
    25-29 Feb. 2008
  • Firstpage
    101
  • Lastpage
    109
  • Abstract
    This paper treats security from a software engineering point of view. Security issues of software components are usually handled at the two levels of development abstractions: by the security experts during the component design, and by the software engineers during the composition of an application system. Security experts identify the threats of the component, define the security policies and functions. On the other hand, the software engineers are more interested in the compositional impact and conformity of the security properties designed and implemented by the security experts. This paper identifies a third level of abstraction: security from the end-users´ perspective. This paper argues that the end-users of the system should know the specific security objectives actually achieved at the system-level. This paper makes the following three specific contributions in this regard: (i) a need for a separate view of security at the end-user level; (ii) the formulation of security goals; (iii) the derivation of security goals for automatic processing.
  • Keywords
    object-oriented programming; security of data; software architecture; automatic processing; component based systems; development abstractions; end-user level; security experts; security functions; security goals; security policy; software components; software engineering; Application software; Computer security; Credit cards; Design engineering; Interconnected systems; Internet; Knowledge engineering; Runtime; Software engineering; Software systems; end users perpective; security goals; security properties; software composition; software service;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Composition-Based Software Systems, 2008. ICCBSS 2008. Seventh International Conference on
  • Conference_Location
    Madrid
  • Print_ISBN
    978-0-7695-3091-8
  • Type

    conf

  • DOI
    10.1109/ICCBSS.2008.22
  • Filename
    4464014