...
首页> 外文期刊>ACM transactions on the web >Test-Based Security Certification of Composite Services
【24h】

Test-Based Security Certification of Composite Services

机译:组合服务的基于测试的安全认证

获取原文
获取原文并翻译 | 示例
           

摘要

The diffusion of service-based and cloud-based systems has created a scenario where software is often made available as services, offered as commodities over corporate networks or the global net. This scenario supports the definition of business processes as composite services, which are implemented via either static or runtime composition of offerings provided by different suppliers. Fast and accurate evaluation of service's security properties becomes then a fundamental requirement and is nowadays part of the software development process. In this article, we show how the verification of security properties of composite services can be handled by test-based security certification and built to be effective and efficient in dynamic composition scenarios. Our approach builds on existing security certification schemes for monolithic services and extends them towards service compositions. It virtually certifies composite services, starting from certificates awarded to the component services. We describe three heuristic algorithms for generating runtime test-based evidence of the composite service holding the properties. These algorithms are compared with the corresponding exhaustive algorithm to evaluate their quality and performance. We also evaluate the proposed approach in a real-world industrial scenario, which considers ENGpay online payment system of Engineering Ingegneria Informatica S.p.A. The proposed industrial evaluation presents the utility and generality of the proposed approach by showing how certification results can be used as a basis to establish compliance to Payment Card Industry Data Security Standard.%3.1-3.43
机译:基于服务和基于云的系统的扩散创造了一种场景,其中软件通常作为服务提供,通过公司网络或全球网络作为商品提供。此业务情景支持将业务流程定义为组合服务,通过不同供应商提供的产品的静态或运行时组合来实现。因此,快速,准确地评估服务的安全性成为一项基本要求,并且如今已成为软件开发过程的一部分。在本文中,我们展示了如何通过基于测试的安全认证来处理组合服务的安全属性验证,以及如何在动态组合方案中构建组合服务的有效性和效率。我们的方法基于整体服务的现有安全认证方案,并将其扩展到服务组合。从授予组件服务的证书开始,它实际上对组合服务进行了认证。我们描述了三种启发式算法,这些算法用于生成基于运行时基于测试的复合服务持有属性的证据。将这些算法与相应的穷举算法进行比较,以评估其质量和性能。我们还将在考虑工业工程学Informatica SpA的ENGpay在线支付系统的现实世界工业场景中评估该提议的方法。该提议的工业评估通过展示如何将认证结果用作基础来提出该方法的实用性和普遍性。建立对支付卡行业数据安全标准的遵守。%3.1-3.43

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号