Towards an enhanced design level security integrating attack trees with statecharts

Omar El Ariss, Jianfei Wu, Dianxiang Xu

Research output: Chapter in Book/Report/Conference proceedingConference contribution

7 Scopus citations

Abstract

Software security has become more and more critical as we are increasingly depending on the Internet an untrustworthy computing environment. Software functionality and security are tightly related to each other vulnerabilities due to design errors inconsistencies incompleteness and missing constraints in system specifications can be wrongly exploited by security attacks. These two concerns however are often handled separately. In this paper we present a threat driven approach that improves on the quality of software through the realization of a more secure functional model. The approach introduces systematic transformation rules and integration steps for mapping attack tree representations into lower level dynamic behavior then integrates this behavior into statechart-based functional models. Through the focus on both the functional and threat behavior software engineers can introduce clearly define and understand security concerns as software is designed. To identify vulnerabilities our approach then applies security analysis and threat identification to the integrated model.

Original languageEnglish (US)
Title of host publicationProceedings - 2011 5th International Conference on Secure Software Integration and Reliability Improvement, SSIRI 2011
Pages1-10
Number of pages10
DOIs
StatePublished - 2011
Event2011 5th International Conference on Secure Software Integration and Reliability Improvement, SSIRI 2011 - Jeju Island, Korea, Republic of
Duration: Jun 27 2011Jun 29 2011

Publication series

NameProceedings - 2011 5th International Conference on Secure Software Integration and Reliability Improvement, SSIRI 2011

Other

Other2011 5th International Conference on Secure Software Integration and Reliability Improvement, SSIRI 2011
Country/TerritoryKorea, Republic of
CityJeju Island
Period6/27/116/29/11

All Science Journal Classification (ASJC) codes

  • Software
  • Safety, Risk, Reliability and Quality

Fingerprint

Dive into the research topics of 'Towards an enhanced design level security integrating attack trees with statecharts'. Together they form a unique fingerprint.

Cite this