首页> 外文期刊>Science of Computer Programming >Formal security analysis for software architecture design: An expressive framework to emerging architectural styles
【24h】

Formal security analysis for software architecture design: An expressive framework to emerging architectural styles

机译:软件架构设计的正式安全性分析:新兴建筑风格的表现力框架

获取原文
获取原文并翻译 | 示例

摘要

Analysing security in the architecture design of modern software systems is a challenging task. Emerging technologies utilised in building software systems may pose security threats, so software engineers need to consider both the structure and behaviour of architectural styles that employ these supporting technologies. This paper presents an automated approach to security analysis that helps to identify security characteristics at the architectural level. Key techniques used by our approach include the use of metrics, vulnerability identification and attack scenarios. Our modelling is expressive in defining architectural styles and security characteristics. Our analysis approach gives insightful results that allow software engineers to trace through the design to find parts of the system that may be impacted by attacks. We have developed an analysis tool that allows user to seamlessly model the software architecture design and analyse security. The evaluation has been conducted to assess the accuracy and performance of our approach. The results show that our analysis approach performs reasonably well to analyse the security in the architectural design.
机译:分析现代软件系统架构设计中的安全性是一个具有挑战性的任务。在构建软件系统中使用的新兴技术可能会造成安全威胁,因此软件工程师需要考虑采用这些支持技术的架构风格的结构和行为。本文提出了一种安全分析的自动化方法,有助于识别架构级别的安全特性。我们方法使用的关键技术包括使用指标,漏洞识别和攻击方案。我们的建模在定义架构风格和安全特性方面是表现力。我们的分析方法提供了识别结果,允许软件工程师通过设计追踪,以查找可能受到攻击影响的系统的部分。我们开发了一个分析工具,允许用户无缝地模拟软件架构设计和分析安全性。已经进行了评估,以评估我们方法的准确性和性能。结果表明,我们的分析方法可相当良好地分析建筑设计中的安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号