Attribute-Based Security Verification of Business Process Models

被引:5
|
作者
Argyropoulos, Nikolaos [1 ]
Mouratidis, Haralambos [1 ]
Fish, Andrew [1 ]
机构
[1] Univ Brighton, Sch Comp Engn & Math, Brighton, E Sussex, England
来源
2017 IEEE 19TH CONFERENCE ON BUSINESS INFORMATICS (CBI), VOL 1 | 2017年 / 1卷
关键词
Business Process Security; Security Verification; Business Process Modelling; BPMN;
D O I
10.1109/CBI.2017.37
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Business processes, as the instruments used by organisations to produce value, need to comply with a number of internally and externally imposed standards and restrictions. Since the majority of such processes involve the exchange of sensitive third party information, their compliance to security constraints needs to be verified before they can be implemented. Current attempts for the verification of security compliance of design-time business process models involve the transformation of both the model and the desired security properties into formal specifications, which can be then used as input for automated model checkers. Such an approach is usually costly both in terms of time and specialised knowledge, while also its coverage can be limited to specific types of security requirements. In this work we introduce an approach for the verification of security in business process models based on structural properties of the workflow of the process. To that end, we introduce a series of attributes to existing BPMN 2.0 concepts and algorithms for checking the compliance of a process model against the most common security requirements. Finally, a real-world business process is used to demonstrate and evaluate the applicability of our proposal.
引用
收藏
页码:43 / 52
页数:10
相关论文
共 50 条
  • [1] Integrating Security Aspects into Business Process Models
    Brucker, Achim D.
    IT-INFORMATION TECHNOLOGY, 2013, 55 (06): : 239 - 245
  • [2] BProVe: A Formal Verification Framework for Business Process Models
    Corradini, Flavio
    Fornari, Fabrizio
    Polini, Andrea
    Re, Barbara
    Tiezzi, Francesco
    Vandin, Andrea
    PROCEEDINGS OF THE 2017 32ND IEEE/ACM INTERNATIONAL CONFERENCE ON AUTOMATED SOFTWARE ENGINEERING (ASE'17), 2017, : 217 - 228
  • [3] Verification of Common Business Rules in BPMN Process Models
    Rachdi, Anass
    En-Nouaary, Abdeslam
    Dahchour, Mohamed
    NETWORKED SYSTEMS, NETYS 2016, 2016, 9944 : 334 - 339
  • [4] Enabling security risk assessment and management for business process models
    Rosado, David G.
    Sanchez, Luis E.
    Jesus Varela-Vaca, Angel
    Santos-Olmo, Antonio
    Teresa Goemez-Loepez, Maria
    Gasca, Rafael M.
    Fernandez-Medina, Eduardo
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2024, 84
  • [5] Data Aware Business Process Models: A Framework for the Analysis and Verification of Properties
    Dell'Aversana, Raffaele
    DECISION ECONOMICS, IN COMMEMORATION OF THE BIRTH CENTENNIAL OF HERBERT A. SIMON 1916-2016 (NOBEL PRIZE IN ECONOMICS 1978), 2016, 475 : 75 - 82
  • [6] Enhancing secure business process design with security process patterns
    Nikolaos Argyropoulos
    Haralambos Mouratidis
    Andrew Fish
    Software and Systems Modeling, 2020, 19 : 555 - 577
  • [7] Enhancing secure business process design with security process patterns
    Argyropoulos, Nikolaos
    Mouratidis, Haralambos
    Fish, Andrew
    SOFTWARE AND SYSTEMS MODELING, 2020, 19 (03) : 555 - 577
  • [8] Supporting Secure Business Process Design via Security Process Patterns
    Argyropoulos, Nikolaos
    Mouratidis, Haralambos
    Fish, Andrew
    ENTERPRISE, BUSINESS-PROCESS AND INFORMATION SYSTEMS MODELING, BPMDS 2017 AND EMMSAD 2017, 2017, 287 : 19 - 33
  • [9] Back to Origin: Transformation of Business Process Models to Business Rules
    Malik, Saleem
    Bajwa, Imran Sarwar
    BUSINESS PROCESS MANAGEMENT WORKSHOPS (BPM), 2013, 132 : 611 - 622
  • [10] Assessing business process models: a literature review on techniques for BPMN testing and formal verification
    Lopes, Tomas
    Guerreiro, Sergio
    BUSINESS PROCESS MANAGEMENT JOURNAL, 2023, 29 (08) : 133 - 162