Model-driven architecture based security analysis

被引:2
作者
Mili, Saoussen [1 ]
Nguyen, Nga [1 ]
Chelouah, Rachid [1 ]
机构
[1] ETIS Lab, Cergy, France
关键词
code generation; embedded systems; MDA; model checking; model transformation; security; SysML;
D O I
10.1002/sys.21581
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
This paper proposes a Model-Driven Architecture approach for the development of an embedded system validation platform namely Model-Based Security Analysis for Embedded Systems (MBSAES). The security properties are formally modeled and verified at an early stage of the design process of the system, which helps to reduce late errors and development time. A separation of the attack scenarios and the system design from the implementation details has been respected. To transform semi-formal models from SysML to NuSVM model checking platform, two Model-to-Text, horizontal and exogenous transformations have been implemented. The first one employs a programming approach with Java to create a Computational Tree Logic specification from an Extended Attack Tree, whereas the second one uses a template approach with Acceleo to generate NuSMV code from SysML structural and behavioral models. To illustrate our approach, a case study, involving attacks aiming to unlock car door systems, via signal jamming and code replaying, is considered. The results of this research will contribute to the automatic validation of system designs against security vulnerabilities via a database of extended attack trees building from existing atomic attacks.
引用
收藏
页码:307 / 321
页数:15
相关论文
共 37 条
[31]   Model Driven Development of Security Aspects [J].
Reznik, Julia ;
Ritter, Tom ;
Schreiner, Rudolf ;
Lang, Ulrich .
ELECTRONIC NOTES IN THEORETICAL COMPUTER SCIENCE, 2007, 163 (02) :65-79
[32]  
Rose L. M., 2012, 2012 Proceedings of 4th International Workshop Modeling in Software Engineering (MiSE 2012), P57, DOI 10.1109/MISE.2012.6226015
[33]  
Roudier Y., 2015, IEEE INT C MOD DRIV, P655
[34]  
Saadatmand M., 2011, INT WORKSH MOD BAS E
[35]  
Sánchez O, 2009, J UNIVERS COMPUT SCI, V15, P2957
[36]  
Systems Modeling Language (SysML) v2 Request For Proposal (RFP), 2017, SYST MOD LANG SYSML
[37]  
Systems Modeling Language version 1.6, 2019, SYST MOD LANG VERS 1