首页> 外文会议>New trends in software methodologies, tools and techniques >An Aspect-Oriented Approach for Software Security Hardening: from Design to Implementation
【24h】

An Aspect-Oriented Approach for Software Security Hardening: from Design to Implementation

机译:一种面向方面的软件安全性增强方法:从设计到实现

获取原文
获取原文并翻译 | 示例

摘要

Security is a very challenging task in software engineering. Enforcing security policies should be taken care of during the early phases of the software development life cycle to prevent security breaches in the final product. Since security is a crosscutting concern that pervades the entire software, integrating security solutions at the software design level may result in scattering and tangling security features throughout the entire design. To address this issue, we propose in this paper an aspect-oriented approach for specifying and enforcing security hardening solutions. This approach provides software designers with UML-based capabilities to perform security hardening in a clear and organized way, at the UML design level, without the need to be security experts. We also present the SHP profile, a UML-based security hardening language to describe and specify security hardening solutions at the UML design level. Finally, we explore the efficiency and the relevance of our approach by applying it to a real world case study and present the experimental results.
机译:在软件工程中,安全性是一项非常具有挑战性的任务。在软件开发生命周期的早期阶段应注意执行安全策略,以防止最终产品出现安全漏洞。由于安全性是贯穿整个软件的一个横切关注点,因此在软件设计级别集成安全性解决方案可能会导致整个设计中的安全性功能分散和混乱。为了解决这个问题,我们在本文中提出了一种面向方面的方法,用于指定和强制执行安全强化解决方案。这种方法为软件设计人员提供了基于UML的功能,可以在UML设计级别以清晰且有条理的方式执行安全性强化,而无需成为安全专家。我们还介绍了SHP配置文件,这是一种基于UML的安全强化语言,用于在UML设计级别描述和指定安全强化解决方案。最后,我们将其应用于实际案例研究中,探索了该方法的效率和相关性,并提出了实验结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号