The design and analysis of security in distributed systems raises numerous questions about the available tools for modeling and verification. It is difficult to ensure the relationship between the selected security solutions and the security concerns in software architecture design. We address this challenge by proposing an integrated approach for specifying and verifying security objectives in component-based software architecture models via reusable formal model libraries of security properties and constraints. Our solution is based on metamodeling techniques for specifying the software architecture structure and on formal techniques for precisely specifying and verifying security properties of a modeled system. We explore a set of representative security objectives from the Confidentiality, Integrity, Availability (CIA) classification. We also use model-driven engineering techniques for the development of a tool suite to support our approach.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Reusable Formal Model Libraries for Specifying and Analyzing Security Objectives in Event-B

  • Loïc Thierry,
  • Brahim Hamid,
  • Jason Jaskolka

摘要

The design and analysis of security in distributed systems raises numerous questions about the available tools for modeling and verification. It is difficult to ensure the relationship between the selected security solutions and the security concerns in software architecture design. We address this challenge by proposing an integrated approach for specifying and verifying security objectives in component-based software architecture models via reusable formal model libraries of security properties and constraints. Our solution is based on metamodeling techniques for specifying the software architecture structure and on formal techniques for precisely specifying and verifying security properties of a modeled system. We explore a set of representative security objectives from the Confidentiality, Integrity, Availability (CIA) classification. We also use model-driven engineering techniques for the development of a tool suite to support our approach.