首页    期刊浏览 2025年07月12日 星期六
登录注册

文章基本信息

  • 标题:An approach to assess and compare quality of security models
  • 本地全文:下载
  • 作者:Matulevičius Raimundas ; Lakk Henri ; Lepmets Marion
  • 期刊名称:Computer Science and Information Systems
  • 印刷版ISSN:1820-0214
  • 电子版ISSN:2406-1018
  • 出版年度:2011
  • 卷号:8
  • 期号:2
  • 页码:447-476
  • DOI:10.2298/CSIS101231014M
  • 出版社:ComSIS Consortium
  • 摘要:

    System security is an important artefact. However security is typically considered only at implementation stage nowadays in industry. This makes it difficult to communicate security solutions to the stakeholders earlier and raises the system development cost, especially if security implementation errors are detected. On the one hand practitioners might not be aware of the approaches that help represent security concerns at the early system development stages. On the other hand a part of the problem might be that there exists only limited support to compare different security development languages and especially their resulting security models. In this paper we propose a systematic approach to assess quality of the security models. To illustrate validity of our proposal we investigate three security models, which present a solution to an industrial problem. One model is created using PL/SQL, a procedural extension language for SQL; another two models are prepared with SecureUML and UMLsec, both characterized as approaches for model-driven security. The study results in a higher quality for the later security models. These contain higher semantic completeness and correctness, they are easier to modify, understand, and facilitate a better communication of security solutions to the system stakeholders than the PL/SQL model. We conclude our paper with a discussion on the requirements needed to adapt the model-driven security approaches to the industrial security analysis.

  • 关键词:Model-driven security development; Modelling quality; PL/SQL; SecureUML; UMLsec
国家哲学社会科学文献中心版权所有