首页> 外文期刊>International Journal of Innovative Computing Information and Control >SECURE BUSINESS PROCESS MODELLING OF SOA APPLICATIONS USING 'UML-SOA-SEC'
【24h】

SECURE BUSINESS PROCESS MODELLING OF SOA APPLICATIONS USING 'UML-SOA-SEC'

机译:使用“ UML-SOA-SEC”对SOA应用程序进行安全的业务流程建模

获取原文
获取原文并翻译 | 示例
           

摘要

Nowadays enterprises are implementing their WIS through SOA using Web services. They are using MDA principles for design and development of WIS and using UML as a modelling language for business process modelling. Along with the increased connectivity in SOA applications, security risks rise exponentially. Security is not defined during the early phases of system development and left onto the developer. Properly configuring security requirements in SOA applications is quite difficult for developers because they are not security experts. Furthermore, SOA security is cross-domain and all required information is not available at downstream phases. Moreover, focus of the currently available security standards and protocols is technology; they do not provide high level of abstraction. Furthermore, a business process expert, who is the actual stakeholder of the business process model is unable to specify security objectives due to lake of security modelling elements in general purpose modelling languages like UML. As a result, he/she either ignores the security intents in his/her model or indicates them in textual way. We are fostering the specification of security intents at high level of abstraction by presenting a security intents DSL containing the essential SOA security objective. It is a UML profile where security intents can be modeled as stereotypes on UML modelling elements during the business process modelling. Aim is to facilitate the business process expert in modelling the security requirements along with the business process modelling. This security annotated business process model will facilitate the security expert in specifying the concrete security implementation. As a proof of work we apply our approach to a typical business process of "on-line flight booking system".
机译:如今,企业正在使用Web服务通过SOA实施其WIS。他们将MDA原理用于WIS的设计和开发,并将UML用作业务流程建模的建模语言。随着SOA应用程序中连接性的提高,安全风险呈指数级增长。在系统开发的早期阶段未定义安全性,而是将安全性留给了开发人员。对于开发人员来说,在SOA应用程序中正确配置安全性要求非常困难,因为他们不是安全性专家。此外,SOA安全性是跨域的,并且所有必需的信息在下游阶段均不可用。此外,当前可用的安全标准和协议的重点是技术。它们不提供高级抽象。此外,由于通用建模语言(例如UML)中的安全建模元素数量众多,业务流程专家(实际上是业务流程模型的涉众)无法指定安全目标。结果,他/她要么忽略了他/她模型中的安全性意图,要么以文本方式表明了它们。通过展示包含基本SOA安全目标的安全意图DSL,我们将在抽象的高度上促进对安全意图的规范。它是一个UML概要文件,在业务流程建模期间,可以将安全意图建模为UML建模元素上的原型。目的是帮助业务流程专家在对安全需求进行建模以及业务流程建模的过程中。这种带有安全注释的业务流程模型将有助于安全专家指定具体的安全实现。作为工作证明,我们将我们的方法应用于“在线航班预订系统”的典型业务流程中。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号