Specification of Information Flow Security Policies in Model-Based Systems Engineering

被引:1
|
作者
Gerking, Christopher [1 ]
机构
[1] Paderborn Univ, Heinz Nixdorf Inst, Paderborn, Germany
来源
SOFTWARE TECHNOLOGIES: APPLICATIONS AND FOUNDATIONS | 2018年 / 11176卷
关键词
Information flow; Security policies; Systems engineering; CYBER-PHYSICAL SYSTEMS; REQUIREMENTS;
D O I
10.1007/978-3-030-04771-9_47
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Model-based systems engineering provides a multi-disciplinary approach to developing cyber-physical systems. Due to their high degree of interconnection, security is a key factor for cyber-physical systems and needs to be front-loaded to the beginning of the development. However, there is a lack of model-based systems engineering approaches that enable the early specification of security policies. As a consequence, security requirements frequently remain unspecified and therefore are hard to satisfy in the downstream development phases. In this paper, we propose to integrate model-based systems engineering with the theory of information flow security. We extend systems engineering models to information flow policies, enabling systems engineers to specify the information flow security requirements of a system under development. On refinement of the resulting models, our approach allows to derive security requirements for individual software components. We illustrate our approach using a model-based design of an autonomous car.
引用
收藏
页码:617 / 632
页数:16
相关论文
共 50 条
  • [11] A Specification Language for Information Security Policies
    Garcia Garcia, Juan Manuel
    PROCEEDINGS OF THE 15TH AMERICAN CONFERENCE ON APPLIED MATHEMATICS AND PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON COMPUTATIONAL AND INFORMATION SCIENCES 2009, VOLS I AND II, 2009, : 437 - +
  • [12] Model-Based Specification and Refinement of Usage Control Policies
    Neisse, Ricardo
    Doerr, Joerg
    2013 ELEVENTH ANNUAL INTERNATIONAL CONFERENCE ON PRIVACY, SECURITY AND TRUST (PST), 2013, : 169 - 176
  • [13] Model-based security engineering with UML
    Jürjens, J
    FOUNDATIONS OF SECURITY ANALYSIS AND DESIGN III, 2005, 3655 : 42 - 77
  • [14] Model-based security engineering for real
    Juerjens, Jan
    FM 2006: FORMAL METHODS, PROCEEDINGS, 2006, 4085 : 600 - 606
  • [15] Model-Based Techniques for Performance Engineering of Business Information Systems
    Kounev, Samuel
    Huber, Nikolaus
    Spinner, Simon
    Brosig, Fabian
    BUSINESS MODELING AND SOFTWARE DESIGN, BMSD 2011, 2012, 109 : 19 - 37
  • [16] A Model-Based Systems Engineering Plugin for Cloud Security Architecture Design
    Dantas Y.G.
    Nigam V.
    Schöpp U.
    SN Computer Science, 5 (5)
  • [17] Model-Based Systems Engineering for Machine Tools and Production Systems (Model-Based Production Engineering)
    Kuebler, Karl
    Scheifele, Stefan
    Scheifele, Christian
    Riedel, Oliver
    4TH INTERNATIONAL CONFERENCE ON SYSTEM-INTEGRATED INTELLIGENCE: INTELLIGENT, FLEXIBLE AND CONNECTED SYSTEMS IN PRODUCTS AND PRODUCTION, 2018, 24 : 216 - 221
  • [18] The challenges of model-based systems engineering for the next generation enterprise information systems
    Zdravkovic, Milan
    Panetto, Herve
    INFORMATION SYSTEMS AND E-BUSINESS MANAGEMENT, 2017, 15 (02) : 225 - 227
  • [19] Ontology for Systems Engineering Model-based Systems Engineering
    van Ruijven, Leo
    2012 Sixth UKSim/AMSS European Symposium on Computer Modelling and Simulation (EMS), 2012, : 371 - 376
  • [20] The challenges of model-based systems engineering for the next generation enterprise information systems
    Milan Zdravković
    Hervé Panetto
    Information Systems and e-Business Management, 2017, 15 : 225 - 227