Validating security design patterns application using model testing

Takanori Kobashi, Nobukazu Yoshioka, Takao Okubo, Haruhiko Kaiya, Hironori Washizaki, Yoshiaki Fukazawa

研究成果: Conference contribution

10 被引用数 (Scopus)

抄録

Software developers are not necessarily security specialists, security patterns provide developers with the knowledge of security specialists. Although security patterns are reusable and include security knowledge, it is possible to inappropriately apply a security pattern or that a properly applied pattern does not mitigate threats and vulnerabilities. Herein we propose a method to validate security pattern applications. Our method provides extended security patterns, which include requirement- and design-level patterns as well as a new model testing process using these patterns. Developers specify the threats and vulnerabilities in the target system during an early stage of development, and then our method validates whether the security patterns are properly applied and assesses whether these vulnerabilities are resolved.

本文言語English
ホスト出版物のタイトルProceedings - 2013 International Conference on Availability, Reliability and Security, ARES 2013
ページ62-71
ページ数10
DOI
出版ステータスPublished - 2013
イベント2013 8th International Conference on Availability, Reliability and Security, ARES 2013 - Regensburg, Germany
継続期間: 2013 9月 22013 9月 6

出版物シリーズ

名前Proceedings - 2013 International Conference on Availability, Reliability and Security, ARES 2013

Conference

Conference2013 8th International Conference on Availability, Reliability and Security, ARES 2013
国/地域Germany
CityRegensburg
Period13/9/213/9/6

ASJC Scopus subject areas

  • 安全性、リスク、信頼性、品質管理

フィンガープリント

「Validating security design patterns application using model testing」の研究トピックを掘り下げます。これらがまとまってユニークなフィンガープリントを構成します。

引用スタイル