A goal oriented approach for Modeling and analyzing security trade-offs

被引:0
作者
Elahi, Golnaz [1 ]
Yu, Eric [1 ]
机构
[1] Univ Toronto, Fac Informat Studies, Toronto, ON M5S 3G6, Canada
来源
CONCEPTUAL MODELING - ER 2007, PROCEEDINGS | 2007年 / 4801卷
关键词
security trade-offs; trade-off analysis; goal modeling; goal model evaluation;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
In designing software systems, security is typically only one design objective among many. It may compete with other objectives such as functionality, usability, and performance. Too often, security mechanisms such as firewalls, access control, or encryption are adopted without explicit recognition of competing design objectives and their origins in stakeholder interests. Recently, there is increasing acknowledgement that security is ultimately about trade-offs. One can only aim for "good enough" security, given the competing demands from many parties. In this paper, we examine how conceptual modeling can provide explicit and systematic support for analyzing security trade-offs. After considering the desirable criteria for conceptual modeling methods, we examine several existing approaches for dealing with security trade-offs. From analyzing the limitations of existing methods, we propose an extension to the i* framework for security trade-off analysis, taking advantage of its multi-agent and goal orientation. The method was applied to several case studies used to exemplify existing approaches.
引用
收藏
页码:375 / +
页数:4
相关论文
共 31 条
  • [1] Anderson Ross., 2001, SECURITY ENG GUIDE B
  • [2] Bass L, 2021, Software Architecture in Practice
  • [3] Bresciani P, 2004, LECT NOTES COMPUT SC, V2940, P35
  • [4] CHUNG L, 2000, NON FUNCTIONAL RQUIR
  • [5] GOAL-DIRECTED REQUIREMENTS ACQUISITION
    DARDENNE, A
    VANLAMSWEERDE, A
    FICKAS, S
    [J]. SCIENCE OF COMPUTER PROGRAMMING, 1993, 20 (1-2) : 3 - 50
  • [6] DEWITT AJ, 2006, P S US PRIV SEC
  • [7] ELAHI G, 2007, GOAL ORIENTED APPROA
  • [8] Modeling security requirements through ownership, permission and delegation
    Giorgini, P
    Massacci, F
    Mylopoulos, J
    Zannone, N
    [J]. 13TH IEEE INTERNATIONAL CONFERENCE ON REQUIREMENTS ENGINEERING, PROCEEDINGS, 2005, : 167 - 176
  • [9] GRANCE T, 2003, GUIDE SELECTING INFO, P800
  • [10] Haley C. B., 2006, P 2006 INT WORKSH SO, P35