A Systematic Approach to Assist Designers in Security Pattern Integration - Université Clermont Auvergne Accéder directement au contenu
Communication Dans Un Congrès Année : 2016

A Systematic Approach to Assist Designers in Security Pattern Integration

Résumé

The last decade has witnessed significant contributions in software engineering to design more secure systems and applications. Software designers can now leverage specific patterns, called security patterns as reusable solutions to model more secure applications. But, despite the advantages offered by security patterns, these are rarely used in practice, because choosing and employing them for devising less vulnerable applications, is still a difficult and error-prone task. In this work, we propose an original approach to guide designers for checking whether a set of security patterns is correctly integrated into models and if vulnerabilities are yet exposed despite their use. This approach relies upon the analysis of the structural and behavioral properties of security patterns and on formal methods to check if these properties hold in the application model completed with patterns. We also provide a metric computation to assess the integration quality of patterns. Afterwards, we check whether the vulnerabilities, which should be removed by the use of patterns, are not exposed in the model. We illustrate this approach on an example of Web application, the Moodle education platform.
Fichier principal
Vignette du fichier
document.pdf (841.33 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-02019284 , version 1 (14-02-2019)

Identifiants

  • HAL Id : hal-02019284 , version 1

Citer

Loukmen Regainia, Cédric Bouhours, Sébastien Salva. A Systematic Approach to Assist Designers in Security Pattern Integration. The Second International Conference on Advances and Trends in Software Engineering (SOFTENG 2016), Feb 2016, lisbon, Portugal. ⟨hal-02019284⟩
64 Consultations
57 Téléchargements

Partager

Gmail Facebook X LinkedIn More