{"title":"Modeling of Security Fault-Tolerant Requirements for Secure Systems","authors":"Don Pathirage, Michael Shin, Dongsoo Jang","doi":"10.1142/s0218194022500644","DOIUrl":null,"url":null,"abstract":"Security services can keep a system from security breaches for a while, but they are ultimately compromised as the system is deployed and used. This paper describes the modeling of security fault-tolerant (SFT) requirements, which can tolerate the failures of security services for systems. SFT requirements are specified together with the security services requirements so that they tolerate breaches of the security services. This paper addresses an approach for specifying and analyzing SFT requirements using a meta-model. Threats to systems are identified in the requirements specification and analysis phases, and SFT measures against the threats are described with security services. An electronic commerce system is selected to illustrate the approach.","PeriodicalId":50288,"journal":{"name":"International Journal of Software Engineering and Knowledge Engineering","volume":" ","pages":""},"PeriodicalIF":0.6000,"publicationDate":"2022-11-16","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"International Journal of Software Engineering and Knowledge Engineering","FirstCategoryId":"94","ListUrlMain":"https://doi.org/10.1142/s0218194022500644","RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q4","JCRName":"COMPUTER SCIENCE, ARTIFICIAL INTELLIGENCE","Score":null,"Total":0}
引用次数: 0
Abstract
Security services can keep a system from security breaches for a while, but they are ultimately compromised as the system is deployed and used. This paper describes the modeling of security fault-tolerant (SFT) requirements, which can tolerate the failures of security services for systems. SFT requirements are specified together with the security services requirements so that they tolerate breaches of the security services. This paper addresses an approach for specifying and analyzing SFT requirements using a meta-model. Threats to systems are identified in the requirements specification and analysis phases, and SFT measures against the threats are described with security services. An electronic commerce system is selected to illustrate the approach.
期刊介绍:
The International Journal of Software Engineering and Knowledge Engineering is intended to serve as a forum for researchers, practitioners, and developers to exchange ideas and results for the advancement of software engineering and knowledge engineering. Three types of papers will be published:
Research papers reporting original research results
Technology trend surveys reviewing an area of research in software engineering and knowledge engineering
Survey articles surveying a broad area in software engineering and knowledge engineering
In addition, tool reviews (no more than three manuscript pages) and book reviews (no more than two manuscript pages) are also welcome.
A central theme of this journal is the interplay between software engineering and knowledge engineering: how knowledge engineering methods can be applied to software engineering, and vice versa. The journal publishes papers in the areas of software engineering methods and practices, object-oriented systems, rapid prototyping, software reuse, cleanroom software engineering, stepwise refinement/enhancement, formal methods of specification, ambiguity in software development, impact of CASE on software development life cycle, knowledge engineering methods and practices, logic programming, expert systems, knowledge-based systems, distributed knowledge-based systems, deductive database systems, knowledge representations, knowledge-based systems in language translation & processing, software and knowledge-ware maintenance, reverse engineering in software design, and applications in various domains of interest.