• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Artikel
  4. Security patterns: Comparing modeling approaches
 
  • Details
  • Full
Options
2011
Book Article
Title

Security patterns: Comparing modeling approaches

Abstract
Addressing the challenges of developing secure software systems remains an active research area in software engineering. Current research efforts have resulted in the documentation of recurring security problems as security patterns. Security patterns provide encapsulated solutions to specific security problems and can be used to build secure systems by designers with little knowledge of security. Despite this benefit, there is lack of work that focus on evaluating the capabilities of security analysis approaches for their support in incorporating security analysis patterns. This chapter presents evaluation results of a study we conducted to examine the extent to which constructs provided by security requirements engineering approaches can support the use of security patterns as part of th e analysis of security problems. To achieve this general objective, we used a specific security pattern and examined the challenges of representing this pattern in some security modeling approaches. We classify the security modeling approaches into two categories: problem and solution and illustrate their capabilities with a well-known security patterns and some practical security examples. Based on the specific security pattern we have used our evaluation results suggest that current approaches to security engineering are, to a large extent, capable of incorporating security analysis patterns.
Author(s)
Nhlabatsi, A.
Bandara, A.
Hayashi, S.
Haley, C.B.
Jürjens, J.
Kaiya, H.
Kubo, A.
Laney, R.
Mouratidis, H.
Nuseibeh, B.
Tahara, Y.
Tun, T.T.
Washizaki, H.
Yoshioka, N.
Yu, Y.
Mainwork
Software engineering for secure systems. Industrial and research perspectives  
DOI
10.4018/978-1-61520-837-1.ch004
Language
English
Fraunhofer-Institut für Software- und Systemtechnik ISST  
Keyword(s)
  • security pattern

  • security pattern representation

  • comparative evaluation

  • UML

  • UMLsec

  • secureUML

  • misuse cases

  • Secure Tropos

  • KAOS

  • problem frames

  • abuse frames

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024