首页> 外文会议>2011 Sixth International Conference on Availability, Reliability and Security >Security Evaluation of Service-oriented Systems with an Extensible Knowledge Base
【24h】

Security Evaluation of Service-oriented Systems with an Extensible Knowledge Base

机译:具有可扩展知识库的面向服务系统的安全性评估

获取原文
获取外文期刊封面目录资料

摘要

Service-oriented software architectures promise enhanced interoperability, reusability, and flexibility for the implementation of business processes. However, assuring the quality of SOA software is challenging due to the distributed, inhomogeneous, and often non-transparent nature of service building blocks. Especially security, which is an overarching quality concern of a system, poses a hard problem for quality assurance in a SOA context. We have developed SiSOA, a method for static security analysis of SOA systems based on reverse-engineering techniques to recover the software architecture and to extract security-related information from available system artifacts. In SiSOA, the extraction and aggregation of security facts is controlled by security rules stored in an extensible knowledge base. In this paper, we describe the structure of the SiSOA knowledge base, its underlying principles, and its role within the SiSOA methodology. We briefly survey our SiSOA prototype tool, and we illustrate the application of knowledge base rules with exemplary security scenarios.
机译:面向服务的软件体系结构承诺增强的互操作性,可重用性和灵活性,以实现业务流程。但是,由于服务构建块的分布式,不均匀且通常是不透明的性质,因此确保SOA软件的质量具有挑战性。尤其是安全性(这是系统的总体质量问题),对于SOA上下文中的质量保证提出了一个难题。我们已经开发了SiSOA,这是一种基于反向工程技术的SOA系统静态安全分析方法,可以恢复软件体系结构并从可用的系统工件中提取与安全相关的信息。在SiSOA中,安全事实的提取和汇总由存储在可扩展知识库中的安全规则控制。在本文中,我们描述了SiSOA知识库的结构,其基本原理及其在SiSOA方法论中的作用。我们简要地调查了我们的SiSOA原型工具,并通过示例性的安全方案说明了知识库规则的应用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号