Engineering Security into Distributed Systems: A Survey of Methodologies

被引:0
作者
Uzunov, Anton V. [1 ]
Fernandez, Eduardo B. [2 ]
Falkner, Katrina [1 ]
机构
[1] Univ Adelaide, Adelaide, SA 5005, Australia
[2] Florida Atlantic Univ, Boca Raton, FL 33431 USA
关键词
Computer Security; Security Engineering; Secure Software Engineering; Distributed Systems; Security Methodologies; Model Driven Security; Secure Software; MODEL-DRIVEN DEVELOPMENT; INFORMATION-SYSTEMS; INTEGRATING SECURITY; ORIENTED APPROACH; DESIGN; REQUIREMENTS; ARCHITECTURE; TROPOS; FRAMEWORK; PATTERNS;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Rapid technological advances in recent years have precipitated a general shift towards software distribution as a central computing paradigm. This has been accompanied by a corresponding increase in the dangers of security breaches, often causing security attributes to become an inhibiting factor for use and adoption. Despite the acknowledged importance of security, especially in the context of open and collaborative environments, there is a growing gap in the survey literature relating to systematic approaches (methodologies) for engineering secure distributed systems. In this paper, we attempt to fill the aforementioned gap by surveying and critically analyzing the state-of-the-art in security methodologies based on some form of abstract modeling (i.e. model-based methodologies) for, or applicable to, distributed systems. Our detailed reviews can be seen as a step towards increasing awareness and appreciation of a range of methodologies, allowing researchers and industry stakeholders to gain a comprehensive view of the field and make informed decisions. Following the comprehensive survey we propose a number of criteria reflecting the characteristics security methodologies should possess to be adopted in real-life industry scenarios, and evaluate each methodology accordingly. Our results highlight a number of areas for improvement, help to qualify adoption risks, and indicate future research directions.
引用
收藏
页码:2920 / 3006
页数:87
相关论文
共 253 条
[51]  
Devanbu Premkumar T., 2000, International Conference on the Future of Software Engineering-ICSE, P227
[52]  
Dolinar K., 2008, TECHNICAL REPORT
[53]  
Dougherty C., 2009, TECHNICAL REPORT
[54]  
Dowd M., 2007, The Art of Software Security Assessment: Identifying and Preventing Software Vulnerabilities
[55]  
Duda M., 2010, THESIS
[56]  
Erl T., 2009, SOA DESIGN PATTERNS, VFirst
[57]  
Fernandez E. B., 1995, Proceedings First IEEE International Conference on Engineering of Complex Comput Systems. Held jointly with 5th CSESAW, 3rd IEEE RTAW and 20th IFAC/IFIP WRTP (Cat. No.95TB100007), P342, DOI 10.1109/ICECCS.1995.479356
[58]  
Fernandez E. B., 1999, Proceedings. Tenth International Workshop on Database and Expert Systems Applications. DEXA 99, P837, DOI 10.1109/DEXA.1999.795291
[59]  
Fernandez EB, 2007, INTEGRATING SECURITY AND SOFTWARE ENGINEERING: ADVANCES AND FUTURE VISIONS, P107
[60]  
Fernandez E. B., 2010, 2010 Proceedings of XXIX International Conference of the Chilean Computer Science Society (SCCC 2010), P66, DOI 10.1109/SCCC.2010.36