Back to Search Start Over

Validating Security Design Patterns Application Using Model Testing

Authors :
Takao Okubo
Haruhiko Kaiya
Takanori Kobashi
Hironori Washizaki
Yoshiaki Fukazawa
Nobukazu Yoshioka
Source :
ARES
Publication Year :
2013
Publisher :
IEEE, 2013.

Abstract

Software developers are not necessarily security specialists, security patterns provide developers with the knowledge of security specialists. Although security patterns are reusable and include security knowledge, it is possible to inappropriately apply a security pattern or that a properly applied pattern does not mitigate threats and vulnerabilities. Herein we propose a method to validate security pattern applications. Our method provides extended security patterns, which include requirement- and design-level patterns as well as a new model testing process using these patterns. Developers specify the threats and vulnerabilities in the target system during an early stage of development, and then our method validates whether the security patterns are properly applied and assesses whether these vulnerabilities are resolved.

Details

Database :
OpenAIRE
Journal :
2013 International Conference on Availability, Reliability and Security
Accession number :
edsair.doi...........c5244e9f2ca0363756c6959e427a032e
Full Text :
https://doi.org/10.1109/ares.2013.13