首页> 外文会议>IEEE International Conference on Big Data Security on Cloud >Embedding Model-Based Security Policies in Software Development
【24h】

Embedding Model-Based Security Policies in Software Development

机译:在软件开发中嵌入基于模型的安全策略

获取原文

摘要

Security in software applications is frequently an afterthought. Even if developers are aware of security policies and software vulnerabilities, they possess little knowledge of how to implement security polices while developing applications. In addition, the lack of support for tools and security automation makes it more challenging to incorporate security policies. In this paper we have proposed a security policy enforcement mechanism to incorporate security policies for data fields in transactions of software application during its development phase. The objective is to facilitate developers implementing security policies easily. The extensibility of our approach gives the flexibility to accommodate different security policy schemas and to implement various security policies on sensitive data. With the simplicity of mapping data fields of business structures with security policy definitions, our approach provides the programmers, business domain experts and security experts a collaborative process to define and incorporate security policies in software.
机译:软件应用程序中的安全性通常是一个事后。即使开发人员了解安全策略和软件漏洞,它们也很少了解如何在开发应用程序时实施安全策略。此外,缺乏对工具和安全自动化的支持使得纳入安全策略更具挑战性。在本文中,我们提出了一种安全策略实施机制,在其开发阶段期间纳入软件应用程序交易中的数据字段的安全策略。目标是促进开发人员轻松实施安全政策。我们的方法的可扩展性使得能够适应不同的安全策略模式,并在敏感数据上实施各种安全策略。借助安全策略定义映射业务结构的数据字段,我们的方法为程序员,业务领域专家和安全专家提供了一个合作过程,用于定义和纳入软件中的安全策略。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号