A Service-oriented Framework for Quantitative Security Analysis of Software Architectures

被引:4
|
作者
Liu, Yanguo [1 ]
Traore, Issa [1 ]
Hoole, Alexander M. [1 ]
机构
[1] Univ Victoria, Dept Elect & Comp Engn, Victoria, BC V8W 2Y2, Canada
来源
2008 IEEE ASIA-PACIFIC SERVICES COMPUTING CONFERENCE, VOLS 1-3, PROCEEDINGS | 2008年
关键词
Architecture Analysis; Security Engineering; Service-oriented Development; Software Metrics; Software Attackability;
D O I
10.1109/APSCC.2008.17
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Software systems today often run in malicious environments in which attacks or intrusions are quite common. This situation has brought security concerns into the development of software systems. Generally, software services are expected not only to satisfy functional requirements but also to be resistant to malicious attacks. Software attackability is defined as the likelihood that an attack on a software system will succeed In this paper, we present a service-oriented framework to analyze attackability of software systems. More specifically, we propose a User System Interaction Effect (USIE) model that can be used systematically to derive and analyze security concerns from service-oriented software architectures. Many aspects of the model derivation and analysis can be automated, which limit the amount of user involvement, and thereby reduce the subjectivity underlying typical security risk analysis process. The model can be used as a foundation for quantitative analysis of software services from different security perspectives.
引用
收藏
页码:1231 / 1238
页数:8
相关论文
共 50 条
  • [1] A security framework for developing service-oriented software architectures
    Rafe, Vahid
    Hosseinpouri, Ramin
    SECURITY AND COMMUNICATION NETWORKS, 2015, 8 (17) : 2957 - 2972
  • [2] Systematic security analysis for service-oriented software architectures
    Liu, Yanguo
    Traore, Issa
    ICEBE 2007: IEEE INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING, PROCEEDINGS, 2007, : 612 - 621
  • [3] Quantitative Analysis of Service-Oriented Architectures
    Iacob, Maria-Eugenia
    Jonkers, Henk
    INTERNATIONAL JOURNAL OF ENTERPRISE INFORMATION SYSTEMS, 2007, 3 (01) : 42 - 60
  • [4] Analysis of Security and Performance Aspects in Service-Oriented Architectures
    Rodrigues, Douglas
    Estrella, Julio C.
    Branco, Kalinka R. L. J. C.
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2011, 5 (01): : 13 - 30
  • [5] Service-oriented Software Architectures in Theory and practice
    Flieder, K.
    ELEKTROTECHNIK UND INFORMATIONSTECHNIK, 2009, 126 (12): : A32 - A35
  • [6] Software visualization in the context of service-oriented architectures
    Eicker, Stefan
    Spies, Thorsten
    Kahl, Christian
    4TH IEEE INTERNATIONAL WORKSHOP ON VISUALIZING SOFTWARE FOR UNDERSTANDING AND ANALYSIS, PROCEEDINGS, 2007, : 108 - +
  • [7] A framework for automated service composition in service-oriented architectures
    Majithia, S
    Walker, DW
    Gray, WA
    SEMANTIC WEB: RESEARCH AND APPLICATIONS, 2004, 3053 : 269 - 283
  • [8] Research on service-Oriented software framework
    Li, Y
    Wu, ZH
    Deng, SG
    GRID AND COOPERATIVE COMPUTING GCC 2004 WORKSHOPS, PROCEEDINGS, 2004, 3252 : 27 - 35
  • [9] A Conceptual Framework for the Governance of Service-Oriented Architectures
    Bernhardt, Jan
    Seese, Detlef
    SERVICE-ORIENTED COMPUTING - ICSOC 2008 WORKSHOPS, 2009, 5472 : 327 - +
  • [10] A framework for simulation models of Service-Oriented Architectures
    Bause, Falko
    Buchholz, Peter
    Kriege, Jan
    Vastag, Sebastian
    PERFORMANCE EVALUATION: METRICS, MODELS AND BENCHMARKS, PROCEEDINGS, 2008, 5119 : 208 - 227