首页> 外文期刊>International journal of secure software engineering >Threat Representation Methods for Composite Service Process Models
【24h】

Threat Representation Methods for Composite Service Process Models

机译:组合服务流程模型的威胁表示方法

获取原文
获取原文并翻译 | 示例
           

摘要

The Business Process Modeling Notation (BPMN) has become a popular standard for expressing high level business processes as well as technical specifications for software systems. However, the specification does not contain native support to express security information, which should not be overlooked in today's world where every organization is exposed to threats and has assets to protect. Although a substantial amount of work enhancing BPMN 1.x with security related information already exists, the opportunities provided by version 2.0 have not received much attention in the security community so far. This paper gives an overview of security in BPMN and investigates several possibilities of representing threats in BPMN 2.0, in particular for design-time specification and runtime execution of composite services with dynamic behavior. Enriching BPMN with threat information enables a process-centric threat modeling approach that complements risk assessment and attack scenarios. We have included examples showing the use of error events, escalation events and text annotations for process, collaboration, choreography and conversation diagrams.
机译:业务流程建模表示法(BPMN)已成为表达高级业务流程以及软件系统技术规范的流行标准。但是,该规范不包含表达安全信息的本地支持,在当今每个组织都面临威胁并拥有保护资产的世界中,不应忽视该支持。尽管已经存在大量工作来增强BPMN 1.x的安全性相关信息,但是到目前为止,版本2.0所提供的机会并未在安全社区中引起太多关注。本文概述了BPMN中的安全性,并研究了在BPMN 2.0中表示威胁的几种可能性,尤其是在设计时指定和具有动态行为的复合服务的运行时执行方面。用威胁信息丰富BPMN可以实现以流程为中心的威胁建模方法,该方法可补充风险评估和攻击方案。我们提供了一些示例,这些示例显示了错误事件,升级事件和文本注释在流程,协作,编排和对话图中的使用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号