Detecting Conflicts Between Data-Minimization and Security Requirements in Business Process Models

被引:11
|
作者
Ramadan, Qusai [1 ]
Strueber, Daniel [1 ]
Salnitri, Mattia [2 ]
Riediger, Volker [1 ]
Juerjens, Jan [1 ,3 ]
机构
[1] Univ Koblenz Landau, Koblenz, Germany
[2] Politecn Milan, Milan, Italy
[3] Fraunhofer Inst Software & Syst Engn ISST, Dortmund, Germany
来源
MODELLING FOUNDATIONS AND APPLICATIONS (ECMFA 2018) | 2018年 / 10890卷
关键词
Conflicts; Security; Data-minimization; BPMN; PRIVACY;
D O I
10.1007/978-3-319-92997-2_12
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Detecting conflicts between security and data-minimization requirements is a challenging task. Since such conflicts arise in the specific context of how the technical and organizational components of the target system interact with each other, their detection requires a thorough understanding of the underlying business processes. For example, a process may require anonymous execution for a task that writes data to a secure data storage, where the identity of the writer is needed for the purpose of accountability. To address this challenge, we propose an extension of the BPMN 2.0 business process modeling language to enable: (i) the specification of process-oriented data-minimization and security requirements, (ii) the detection of conflicts between these requirements based on a catalog of domain-independent anti-patterns. The considered security requirements were reused from SecBPMN2, a security-oriented extension of BPMN 2.0, while the data-minimization part is new. SecBPMN2 also provides a graphical query language called SecBPMN2-Q, which we extended to formulate our anti-patterns. We report on feasibility and usability of our approach based on a case study featuring a healthcare management system, and an experimental user study.
引用
收藏
页码:179 / 198
页数:20
相关论文
共 16 条
  • [1] A semi-automated BPMN-based framework for detecting conflicts between security, data-minimization, and fairness requirements
    Ramadan, Qusai
    Strueber, Daniel
    Salnitri, Mattia
    Juerjens, Jan
    Riediger, Volker
    Staab, Steffen
    SOFTWARE AND SYSTEMS MODELING, 2020, 19 (05) : 1191 - 1227
  • [2] A semi-automated BPMN-based framework for detecting conflicts between security, data-minimization, and fairness requirements
    Qusai Ramadan
    Daniel Strüber
    Mattia Salnitri
    Jan Jürjens
    Volker Riediger
    Steffen Staab
    Software and Systems Modeling, 2020, 19 : 1191 - 1227
  • [3] A Framework Managing Conflicts between Security and Privacy Requirements
    Alkubaisy, Duaa
    2017 11TH INTERNATIONAL CONFERENCE ON RESEARCH CHALLENGES IN INFORMATION SCIENCE (RCIS), 2017, : 427 - 432
  • [4] Conflicts Between Security and Privacy Measures in Software Requirements Engineering
    Ganji, Daniel
    Mouratidis, Haralambos
    Gheytassi, Saeed Malekshahi
    Petridis, Miltos
    GLOBAL SECURITY, SAFETY AND SUSTAINABILITY: TOMORROW'S CHALLENGES OF CYBER SECURITY, ICGS3 2015, 2015, 534 : 323 - 334
  • [5] Obtaining secure business process models from an enterprise architecture considering security requirements
    San Martin, Luis
    Rodriguez, Alfonso
    Caro, Angelica
    Velasquez, Ignacio
    BUSINESS PROCESS MANAGEMENT JOURNAL, 2022, 28 (01) : 150 - 177
  • [6] Integrating Security Aspects into Business Process Models
    Brucker, Achim D.
    IT-INFORMATION TECHNOLOGY, 2013, 55 (06): : 239 - 245
  • [7] Integration of Data Envelopment Analysis in Business Process Models: A Novel Approach to Measure Information Security
    Akerlund, Agnes
    Grosse, Christine
    ICISSP: PROCEEDINGS OF THE 6TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2020, : 281 - 288
  • [8] Attribute-Based Security Verification of Business Process Models
    Argyropoulos, Nikolaos
    Mouratidis, Haralambos
    Fish, Andrew
    2017 IEEE 19TH CONFERENCE ON BUSINESS INFORMATICS (CBI), VOL 1, 2017, 1 : 43 - 52
  • [9] Enabling security risk assessment and management for business process models
    Rosado, David G.
    Sanchez, Luis E.
    Jesus Varela-Vaca, Angel
    Santos-Olmo, Antonio
    Teresa Goemez-Loepez, Maria
    Gasca, Rafael M.
    Fernandez-Medina, Eduardo
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2024, 84
  • [10] Application of Heuristics in Business Process Models to Support Software Requirements Specification
    Nogueira, Fernando Aparecido
    de Oliveira, Hilda Carvalho
    ICEIS: PROCEEDINGS OF THE 19TH INTERNATIONAL CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS - VOL 2, 2017, : 40 - 51