Threat Analysis in Goal-Oriented Security Requirements Modelling

P. H. Meland, E. Paja, Erlend Andreas Gjære, S. Paul, F. Dalpiaz, P. Giorgini
{"title":"Threat Analysis in Goal-Oriented Security Requirements Modelling","authors":"P. H. Meland, E. Paja, Erlend Andreas Gjære, S. Paul, F. Dalpiaz, P. Giorgini","doi":"10.4018/IJSSE.2014040101","DOIUrl":null,"url":null,"abstract":"Goal and threat modelling are important activities of security requirements engineering: goals express why a system is needed, while threats motivate the need for security. Unfortunately, existing approaches mostly consider goals and threats separately, and thus neglect the mutual influence between them. In this paper, the authors address this deficiency by proposing an approach that extends goal modelling with threat modelling and analysis. The authors show that this effort is not trivial and a trade-off between visual expressiveness, usability and usefulness has to be considered. Specifically, the authors integrate threat modelling with the socio-technical security modelling language (STS-ml), introduce automated analysis techniques that propagate threats in the combined models, and present tool support that enables reuse of threats facilitated by a threat repository. The authors illustrate their approach on a case study from the Air Traffic Management (ATM) domain, from which they extract some practical challenges. The authors conclude that threats provide a useful foundation and justification for the security requirements that the authors derive from goal modelling, but this should not be considered as a replacement to risk assessment. The usage of goals and threats early in the development process allows raising awareness of high-level security issues that occur regardless of the chosen technology and organizational processes.","PeriodicalId":89158,"journal":{"name":"International journal of secure software engineering","volume":"56 1","pages":"1-19"},"PeriodicalIF":0.0000,"publicationDate":"2014-04-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"21","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"International journal of secure software engineering","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.4018/IJSSE.2014040101","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 21

Abstract

Goal and threat modelling are important activities of security requirements engineering: goals express why a system is needed, while threats motivate the need for security. Unfortunately, existing approaches mostly consider goals and threats separately, and thus neglect the mutual influence between them. In this paper, the authors address this deficiency by proposing an approach that extends goal modelling with threat modelling and analysis. The authors show that this effort is not trivial and a trade-off between visual expressiveness, usability and usefulness has to be considered. Specifically, the authors integrate threat modelling with the socio-technical security modelling language (STS-ml), introduce automated analysis techniques that propagate threats in the combined models, and present tool support that enables reuse of threats facilitated by a threat repository. The authors illustrate their approach on a case study from the Air Traffic Management (ATM) domain, from which they extract some practical challenges. The authors conclude that threats provide a useful foundation and justification for the security requirements that the authors derive from goal modelling, but this should not be considered as a replacement to risk assessment. The usage of goals and threats early in the development process allows raising awareness of high-level security issues that occur regardless of the chosen technology and organizational processes.
面向目标的安全需求建模中的威胁分析
目标和威胁建模是安全需求工程的重要活动:目标表示为什么需要一个系统,而威胁则激发对安全的需求。不幸的是,现有的方法大多将目标和威胁分开考虑,从而忽略了它们之间的相互影响。在本文中,作者通过提出一种扩展目标建模与威胁建模和分析的方法来解决这一缺陷。作者表示,这种努力不是微不足道的,必须考虑视觉表现力、可用性和有用性之间的权衡。具体来说,作者将威胁建模与社会技术安全建模语言(STS-ml)集成在一起,引入了在组合模型中传播威胁的自动化分析技术,并提供了工具支持,可以通过威胁存储库促进威胁的重用。作者通过空中交通管理(ATM)领域的一个案例研究说明了他们的方法,并从中提取了一些实际挑战。作者的结论是,威胁为作者从目标建模中得出的安全需求提供了一个有用的基础和理由,但这不应该被视为风险评估的替代品。在开发过程的早期使用目标和威胁可以提高对高级安全问题的认识,无论所选择的技术和组织过程如何。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信