...
首页> 外文期刊>International Journal of Engineering Science and Technology >Security Architectures for Model Driven Web Requirements Financial Application Case Study
【24h】

Security Architectures for Model Driven Web Requirements Financial Application Case Study

机译:模型驱动的Web需求财务应用程序的安全体系结构案例研究

获取原文
           

摘要

MDA with executable UML offers an approach that embodies all the key ingredients of the process for developing dependable systems, by offering: A uniform strategy for preserving investment in existing models built using unsupported tools, by automatically migrating them to profiled UML models for subsequent maintenance and development using state of the art UML tools; A clean separation of application behavior from the platform specific implementation using technologies such as Integrated Modular Avionics (IMA), allowing the full potential of IMA to be realized in a consistent and dependable way; A semantically well defined formalism that can be used a basis for modular certification of safety related systems; The ability to generate not only the components of the target system, but components of development tool chain, providing scope for model translation and offering executable specifications that can be tested early and mapped reliably onto the target, leading to greater levels of dependency. MDA is a new approach for most organizations, and therefore carries additional training and learning curve costs and also currently the availability of production quality code generators is currently limited. MDA requires developers to work at a more level than code although experience shows that most do not have any difficulty making the adjustment, there will be some who find this change of emphasis difficult to achieve. Building upon the initial success of MDA deployment so far, work is now proceeding on the enhancement of Ada code mapping rules to cover the entire xUML formalism. Work is also underway to develop a generic adapter/router component to provide a standard component to provide a standard way to interface re-engineered xUML components with pre-existing components. These techniques are now being applied to another avionics system in the same organization, in response to the customers need for a faster and cheaper upgrade capability. While we consider systematically all actions within a use case and analyze how they could be subverted, it produces all (or most) of the threats to a given application. While all this could be done in textual version of the use case, the use of UML activity diagrams produces a clear and more intuitive way to analyze these attacks. From the threats we derive necessary policies to stop or mitigate them.
机译:具有可执行UML的MDA通过以下方式提供了一种体现开发可靠系统的过程的所有关键要素的方法:提供一种统一策略,用于保留对使用不受支持工具构建的现有模型的投资,方法是将其自动迁移到概要分析的UML模型以进行后续维护和维护。使用最新的UML工具进行开发;使用诸如集成模块化航空电子(IMA)之类的技术将应用程序行为与特定于平台的实现完全分开,从而以一致且可靠的方式实现IMA的全部潜力;语义上定义明确的形式主义,可以用作安全相关系统的模块化认证的基础;不仅可以生成目标系统的组件,还可以生成开发工具链的组件,从而提供了模型转换的范围,并提供了可以进行早期测试并可靠地映射到目标上的可执行规范,从而提高了依赖性。 MDA是大多数组织的一种新方法,因此会带来额外的培训和学习成本,并且当前生产质量代码生成器的可用性也受到限制。 MDA要求开发人员比代码工作更多的层次,尽管经验表明大多数人在进行调整时没有任何困难,但是有些人会发现这种重点的改变很难实现。在迄今为止MDA部署取得初步成功的基础上,现在正在着手增强Ada代码映射规则,以覆盖整个xUML形式主义。还正在进行开发通用适配器/路由器组件的工作,以提供一个标准组件,从而提供一种将重新设计的xUML组件与现有组件接口的标准方法。现在,这些技术已被应用于同一组织中的另一个航空电子系统,以响应客户对更快,更便宜的升级功能的需求。尽管我们系统地考虑了用例中的所有动作并分析了如何将其颠覆,但它会对给定的应用程序产生所有(或大部分)威胁。尽管所有这些都可以在用例的文本版本中完成,但是使用UML活动图可以产生一种清晰,更直观的方式来分析这些攻击。从威胁中,我们得出了制止或减轻威胁的必要策略。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号