• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Scopus
  4. Secure Data-Flow Compliance Checks between Models and Code based on Automated Mappings (Summary)
 
  • Details
  • Full
Options
2020
Conference Paper
Title

Secure Data-Flow Compliance Checks between Models and Code based on Automated Mappings (Summary)

Abstract
We present our paper published at the 2019 edition of the International Conference on Model Driven Engineering Languages and Systems (MODELS) [Pe19]. During the development of security-critical software, the system implementation must capture the security properties postulated by the architectural design. To iteratively guide the developer in discovering such compliance violations we introduce automated mappings. These mappings are created by searching for correspondences between a design-level model (Security Data Flow Diagram) and an implementation-level model (Program Model). We limit the search space by considering name similarities between model elements and code elements as well as by the use of heuristic rules for matching data-flow structures. The automated mappings support the designer in an early discovery of implementation absence, convergence, and divergence with respect to the planned software design as well as the discovery of secure data-flow compliance violations. We provide a publicly available implementation of the approach and its evaluation on five open source Java projects.
Author(s)
Peldszus, Sven Matthias
Universität Koblenz
Tuma, Katja
Göteborgs Universitet
Strüber, Daniel G.
Göteborgs Universitet
Jürjens, Jan  
Fraunhofer Institute for Software and Systems Engineering ISST  
Scandariato, Riccardo
Göteborgs Universitet
Mainwork
Lecture Notes in Informatics Lni Proceedings Series of the Gesellschaft Fur Informatik Gi
Conference
Fachtagung des GI-Fachbereichs Softwaretechnik, Software Engineering 2020 - Conference of the GI Special Interest Group on Software Engineering, Software Engineering 2020
DOI
10.18420/SE2020_13
Language
English
Fraunhofer-Institut für Software- und Systemtechnik ISST  
  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024