首页> 外文OA文献 >A Model-Driven Engineering approach with Diagnosis of Non-Conformance of Security Objectives in Business Process Models
【2h】

A Model-Driven Engineering approach with Diagnosis of Non-Conformance of Security Objectives in Business Process Models

机译:诊断业务流程模型中安全目标不符合的模型驱动工程方法

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Several reports indicate that the highest businesspriorities include: business improvement, security, and IT management.The importance of security and risk management isgaining that even government statements in some cases haveimposed the inclusion of security and risk management withinbusiness management. Risk assessment has become an essentialmechanism for business security analysts, since it allows theidentification and evaluation of any threats, vulnerabilities, andrisks to which organizations maybe be exposed. In this work, aframework based on the concepts of Model-Driven Developmenthas been proposed. The framework provides different stageswhich range from a high abstraction level to an executable level.The main contribution lie in the presentation of an extension ofa business process meta-model which includes risk informationbased on standard approaches. The meta-model provides necessarycharacteristics for the risk assessment of business processmodels at an abstract level of the approach. The framework hasbeen equipped with specific stages for the automatic validation ofbusiness processes using model-based diagnosis which permits thedetection of the non-conformance of security objectives specified.The validation stages ensure that business processes are correctwith regard to the objectives specified by the customer beforethey are transformed into executable processes.
机译:几份报告表明,最高的业务优先级包括:业务改进,安全性和IT管理。安全性和风险管理的重要性日益凸显,甚至在某些情况下,即使政府声明也已将安全性和风险管理纳入了业务管理。风险评估已成为业务安全分析人员不可或缺的机制,因为它可以识别和评估组织可能面临的任何威胁,漏洞和风险。在这项工作中,提出了基于模型驱动开发概念的框架。该框架提供了从高抽象级别到可执行级别的不同阶段。主要贡献在于对业务流程元模型的扩展的表示,其中包括基于标准方法的风险信息。元模型在方法的抽象级别上为业务流程模型的风险评估提供了必要的特征。该框架已经配备了特定的阶段,可以使用基于模型的诊断来自动验证业务流程,从而可以检测到所指定的安全目标是否不合格。验证阶段可以确保业务流程对于客户指定的目标而言是正确的,然后再进行验证。转换为可执行程序。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号