• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. Connecting security requirements analysis and secure design using patterns and UMLsec
 
  • Details
  • Full
Options
2011
Conference Paper
Title

Connecting security requirements analysis and secure design using patterns and UMLsec

Abstract
Existing approaches only provide informal guidelines for the transition from security requirements to secure design. Carrying out this transition is highly non-trivial and error-prone, leaving the risk of introducing vulnerabilities. This paper presents a pattern-oriented approach to connect security requirements analysis and secure architectural design. Following the divide & conquer principle, a software development problem is divided into simpler subproblems based on security requirements analysis patterns. We complement each of these patterns with architectural security patterns tailored to solve classes of security subproblems. We use UMLsec together with the advanced modeling possibilities for software architectures of UML 2.3 to equip the architectural security patterns with security properties, and to allow tool-supported analysis and composition of instances of these patterns. We validate our approach using two case studies and illustrate its support for Common Criteria certifications.
Author(s)
Schmidt, H.
Jürjens, J.
Mainwork
Advanced information systems engineering. 23rd international conference, CAiSE 2011  
Conference
International Conference on Advanced Information Systems Engineering (CAiSE) 2011  
DOI
10.1007/978-3-642-21640-4_28
Additional full text version
Landing Page
Language
English
Fraunhofer-Institut für Software- und Systemtechnik ISST  
  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024