From Goal-Driven Security Requirements Engineering to Secure Design

被引:35
作者
Mouratidis, Haralambos [1 ]
Jurjens, Jan [2 ,3 ]
机构
[1] Univ E London, Sch Comp Informat Technol & Engn, London E16 2RD, England
[2] TU Dortmund, Dortmund, Germany
[3] Fraunhofer ISST, Dortmund, Germany
关键词
FRAMEWORK;
D O I
10.1002/int.20432
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Security of intelligent software systems is an important area of research. Although security is traditionally considered a technical issue; security is, in fact, a two-dimensional problem, which involves technical as well as social challenges. Goal-driven requirements engineering (GDRE) has been proposed in the literature as a suitable paradigm for the analysis of security issues and elicitation of security requirements at both the social and technical level. Nevertheless, there is lack of approaches, which would support the successful transformation of the elicited, using GDRE approaches, security requirements to design. This paper presents work that fills this gap. The presented approach, which is based on the integration of a goal-driven security requirements engineering (GDSRE) methodology and a model-based security engineering (MBSE) method, has some important features: (1) It provides a structured process to translate the results of the GDSRE method to a design, which satisfies these requirements; (2) it allows the simultaneous elicitation and analysis of the security requirements and the functional requirements of the system; (3) it allows consideration of both the social and the technical dimensions of the system's security; (4) it guides software engineers toward a design that is amenable to formal verification with the aid of automated tools. We demonstrate the applicability of the proposed approach at the hand of an application to the electronic purse standard common electronic purse specifications (released by Visa International and others). (c) 2010 Wiley Periodicals, Inc.
引用
收藏
页码:813 / 840
页数:28
相关论文
共 50 条
  • [21] An Effective Security Requirements Engineering Framework for Cyber-Physical Systems
    Rehman, Shafiq Ur
    Gruhn, Volker
    TECHNOLOGIES, 2018, 6 (03):
  • [22] A mixed integer goal programming model for discrete values of design requirements in QFD
    Delice, Elif Kilic
    Gungor, Zulal
    INTERNATIONAL JOURNAL OF PRODUCTION RESEARCH, 2011, 49 (10) : 2941 - 2957
  • [23] Policy-Enabled Goal-Oriented Requirements Engineering for Semantic Business Process Management
    Decreus, Ken
    Poels, Geert
    El Kharbili, Marwane
    Pulvermueller, Elke
    INTERNATIONAL JOURNAL OF INTELLIGENT SYSTEMS, 2010, 25 (08) : 784 - 812
  • [24] Profile model for management of sustainability integration in engineering design requirements
    Watz, Matilda
    Hallstedt, Sophie I.
    JOURNAL OF CLEANER PRODUCTION, 2020, 247
  • [25] Security Requirements Engineering (SRE) Framework for Cyber-Physical Systems (CPS): SRE for CPS
    ur Rehman, Shafiq
    Gruhn, Volker
    NEW TRENDS IN INTELLIGENT SOFTWARE METHODOLOGIES, TOOLS AND TECHNIQUES, 2017, 297 : 153 - 163
  • [26] Eliciting security requirements and tracing them to design: an integration of Common Criteria, heuristics, and UMLsec
    Houmb, Siv Hilde
    Islam, Shareeful
    Knauss, Eric
    Jurjens, Jan
    Schneider, Kurt
    REQUIREMENTS ENGINEERING, 2010, 15 (01) : 63 - 93
  • [27] A systematic literature review of model-driven security engineering for cyber-physical systems
    Geismann, Johannes
    Bodden, Eric
    JOURNAL OF SYSTEMS AND SOFTWARE, 2020, 169
  • [28] Goal-Oriented Requirements Analysis and an Extended Design Pattern using Scala for Artificial Intelligence Programming Contests
    Sakamoto, Kazunori
    Hosono, Hiroaki
    Sato, Seiji
    Washizaki, Hironori
    Fukazawa, Yoshiaki
    2013 3RD INTERNATIONAL WORKSHOP ON GAMES AND SOFTWARE ENGINEERING: ENGINEERING COMPUTER GAMES TO ENABLE POSITIVE, PROGRESSIVE CHANGE (GAS), 2013, : 32 - 35
  • [29] Data-driven engineering design: A systematic review using scientometric approach
    Vlah, Daria
    Kastrin, Andrej
    Povh, Janez
    Vukasinovic, Nikola
    ADVANCED ENGINEERING INFORMATICS, 2022, 54
  • [30] ModelViz: A Model-Driven Engineering Approach for Visual Analytics System Design
    Khakpour, Alireza
    Vazquez-Ingelmo, Andrea
    Colomo-Palacios, Ricardo
    Garcia-Penalvo, Francisco J.
    Martini, Antonio
    IEEE ACCESS, 2024, 12 : 42667 - 42682