Abstract
Selecting security mechanisms for complex software systems is a cumbersome process. The presence of multiple goals and architectural components, as well as cost and performance considerations, render decision-making a crucial but complicated aspect of a system’s design. In our work, we extend Secure Tropos, a security requirements engineering methodology, by introducing the concept of Risk in order to facilitate the elicitation and analysis of security requirements and also support a systematic risk assessment process during the system’s design time. Next, we use Constrained Goal Models to reason about optimal security mechanism combinations with respect to multiple objectives of the system-to-be, taking into account conflicting functional and non-functional goals. This type of reasoning allows combining linear multi-objective optimisation with logical constraints introduced by the system’s stakeholders. Finally, we illustrate the application of approach through a real-world case study from the e-government sector.
Original language | English |
---|---|
Title of host publication | Computer Security - ESORICS 2017 International Workshops, CyberICPS 2017 and SECPRE 2017, Revised Selected Papers |
Publisher | Springer-Verlag |
Pages | 262-280 |
Number of pages | 19 |
ISBN (Electronic) | 9783319728179 |
ISBN (Print) | 9783319728162 |
DOIs | |
Publication status | Published - 22 Dec 2017 |
Event | 3rd Workshop on Security of Industrial Control Systems and Cyber-Physical Systems, CyberICPS 2017, 1st International Workshop on Security and Privacy Requirements Engineering, SECPRE 2017, Both workshops were co-located with 22nd European Symposium on Research in Computer Security, ESORICS 2017 - Oslo, Norway Duration: 14 Sep 2017 → 15 Sep 2017 |
Publication series
Name | Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) |
---|---|
Volume | 10683 LNCS |
ISSN (Print) | 0302-9743 |
ISSN (Electronic) | 1611-3349 |
Workshop
Workshop | 3rd Workshop on Security of Industrial Control Systems and Cyber-Physical Systems, CyberICPS 2017, 1st International Workshop on Security and Privacy Requirements Engineering, SECPRE 2017, Both workshops were co-located with 22nd European Symposium on Research in Computer Security, ESORICS 2017 |
---|---|
Country | Norway |
City | Oslo |
Period | 14/09/17 → 15/09/17 |
Keywords
- Constraint goal models
- Decision making
- Information security
- Security requirements
Fingerprint Dive into the research topics of 'Decision-making in security requirements engineering with constrained goal models'. Together they form a unique fingerprint.
Profiles
-
Haris Mouratidis
- School of Computing, Engineering & Maths - Prof of Software Systems Engineering
- Centre for Secure, Intelligent and Usable Systems
Person: Academic