...
首页> 外文期刊>Information and software technology >Automated Analysis Of Security-design Models
【24h】

Automated Analysis Of Security-design Models

机译:安全设计模型的自动分析

获取原文
获取原文并翻译 | 示例

摘要

We have previously proposed SecureUML, an expressive UML-based language for constructing security-design models, which are models that combine design specifications for distributed systems with specifications of their security policies. Here, we show how to automate the analysis of such models in a semantically precise and meaningful way. In our approach, models are formalized together with scenarios that represent possible run-time instances. Queries about properties of the security policy modeled are expressed as formulas in UML's Object Constraint Language. The policy may include both declarative aspects, i.e., static access-control information such as the assignment of users and permissions to roles, and programmatic aspects, which depend on dynamic information, namely the satisfaction of authorization constraints in a given scenario. We show how such properties can be evaluated, completely automatically, in the context of the metamodel of the security-design language. We demonstrate, through examples, that this approach can be used to formalize and check non-trivial security properties. The approach has been implemented in the SecureMOVA tool and all of the examples presented have been checked using this tool.
机译:我们之前曾提出过SecureUML,这是一种用于构建安全设计模型的,基于UML的表达语言,该模型是将分布式系统的设计规范与其安全策略规范结合在一起的模型。在这里,我们展示了如何以语义精确和有意义的方式自动分析此类模型。在我们的方法中,模型与代表可能的运行时实例的方案一起形式化。有关建模的安全策略的属性的查询以UML的对象约束语言中的公式表示。该策略可以包括声明性方面,即静态访问控制信息,例如用户和角色的权限分配,以及程序性方面,这取决于动态信息,即在给定场景下对授权约束的满足。我们展示了如何在安全设计语言的元模型的上下文中完全自动地评估这些属性。通过示例,我们证明该方法可用于形式化和检查非平凡的安全属性。该方法已在SecureMOVA工具中实现,并且已使用此工具检查了所提供的所有示例。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号