MBSEsec: Model-Based Systems Engineering Method for Creating Secure Systems

被引:13
作者
Mazeika, Donatas [1 ]
Butleris, Rimantas [1 ]
机构
[1] Kaunas Univ Technol, Ctr Informat Syst Design Technol, LT-51423 Kaunas, Lithuania
来源
APPLIED SCIENCES-BASEL | 2020年 / 10卷 / 07期
关键词
MBSE; security; MBSEsec; SysML; REQUIREMENTS; SAFETY;
D O I
10.3390/app10072574
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
This paper presents how Model-Based System Engineering (MBSE) could be leveraged in order to mitigate security risks at an early stage of system development. Primarily, MBSE was used to manage complex engineering projects in terms of system requirements, design, analysis, verification, and validation activities, leaving security aspects aside. However, previous research showed that security requirements and risks could be tackled in the MBSE model, and powerful MBSE tools such as simulation, change impact analysis, automated document generation, validation, and verification could be successfully reused in the multidisciplinary field. This article analyzes various security-related techniques and then clarifies how these techniques can be represented in the Systems Modeling Language (SysML) model and then further exploited with MBSE tools. The paper introduces the MBSEsec method, which gives guidelines for the security analysis process, the SysML/UML-based security profile, and recommendations on what security technique is needed at each security process phase. The MBSEsec method was verified by creating an application case study that reflects real-world problems and running an experiment where systems and security engineers evaluated the feasibility of our approach.
引用
收藏
页数:18
相关论文
共 24 条
  • [1] [Anonymous], 2017, P 12 SYST SYST ENG C
  • [2] [Anonymous], 2016, INTEL AUTOMOTIVE SEC
  • [3] [Anonymous], 2013, 27001 ISOIEC
  • [4] Carroll E., 2016, SYSTEMATIC LIT REV I
  • [5] Chattopadhyay A, 2018, AUSTR U POW ENG C AU, P1
  • [6] Dubois E, 2010, INTENTIONAL PERSPECTIVES ON INFORMATION SYSTEMS ENGINEERING, P289, DOI 10.1007/978-3-642-12544-7_16
  • [7] Evans Rhys., 2010, 2010 5 INT C SYSTEM, DOI [DOI 10.1109/SYSOSE.2010.5544065, 10.1109/SYSOSE.2010.5544065]
  • [8] International Council on Systems Engineering, 2007, SYST ENG HDB VERS 3
  • [9] Tools for secure systems development with UML
    Jan Jürjens
    Pasha Shabalin
    [J]. International Journal on Software Tools for Technology Transfer, 2007, 9 (5-6) : 527 - 544
  • [10] Jurjens J., 2002, UML 2002 The Unified Modeling Language, V2460, P1