GI LogoGI Logo
  • Anmelden
Digitale Bibliothek
    • Gesamter Bestand

      • Bereiche & Sammlungen
      • Titel
      • Autor
      • Erscheinungsdatum
      • Schlagwort
    • Diese Sammlung

      • Titel
      • Autor
      • Erscheinungsdatum
      • Schlagwort
Digital Bibliothek der Gesellschaft für Informatik e.V.
GI-DL
    • English
    • Deutsch
  • Deutsch 
    • English
    • Deutsch
Dokumentanzeige 
  •   Startseite
  • Lecture Notes in Informatics
  • Proceedings
  • Software Engineering
  • P300 - Software Engineering 2020
  • Dokumentanzeige
JavaScript is disabled for your browser. Some features of this site may not work without it.
  •   Startseite
  • Lecture Notes in Informatics
  • Proceedings
  • Software Engineering
  • P300 - Software Engineering 2020
  • Dokumentanzeige

Secure Data-Flow Compliance Checks between Models and Code based on Automated Mappings (Summary)

Autor(en):
Peldszus, Sven [DBLP] ;
Tuma, Katja [DBLP] ;
Strüber, Daniel [DBLP] ;
Jürjens, Jan [DBLP] ;
Scandariato, Riccardo [DBLP]
Zusammenfassung
We present our paper published at the 2019 edition of the International Conference on Model Driven Engineering Languages and Systems (MODELS). During the development of security-critical software, the system implementation must capture the security properties postulated by the architectural design. To iteratively guide the developer in discovering such compliance violations we introduce automated mappings. These mappings are created by searching for correspondences between a design-level model (Security Data Flow Diagram) and an implementation-level model (Program Model). We limit the search space by considering name similarities between model elements and code elements as well as by the use of heuristic rules for matching data-flow structures. The automated mappings support the designer in an early discovery of implementation absence, convergence, and divergence with respect to the planned software design as well as the discovery of secure data-flow compliance violations. We provide a publicly available implementation of the approach and its evaluation on five open source Java projects.
  • Vollständige Referenz
  • BibTeX
Peldszus, S., Tuma, K., Strüber, D., Jürjens, J. & Scandariato, R., (2020). Secure Data-Flow Compliance Checks between Models and Code based on Automated Mappings (Summary). In: Felderer, M., Hasselbring, W., Rabiser, R. & Jung, R. (Hrsg.), Software Engineering 2020. Bonn: Gesellschaft für Informatik e.V.. (S. 51--52). DOI: 10.18420/SE2020_13
@inproceedings{mci/Peldszus2020,
author = {Peldszus, Sven AND Tuma, Katja AND Strüber, Daniel AND Jürjens, Jan AND Scandariato, Riccardo},
title = {Secure Data-Flow Compliance Checks between Models and Code based on Automated Mappings (Summary)},
booktitle = {Software Engineering 2020},
year = {2020},
editor = {Felderer, Michael AND Hasselbring, Wilhelm AND Rabiser, Rick AND Jung, Reiner} ,
pages = { 51--52 } ,
doi = { 10.18420/SE2020_13 },
publisher = {Gesellschaft für Informatik e.V.},
address = {Bonn}
}
DateienGroesseFormatAnzeige
B3-04.pdf65.64Kb PDF Öffnen

Sollte hier kein Volltext (PDF) verlinkt sein, dann kann es sein, dass dieser aus verschiedenen Gruenden (z.B. Lizenzen oder Copyright) nur in einer anderen Digital Library verfuegbar ist. Versuchen Sie in diesem Fall einen Zugriff ueber die verlinkte DOI: 10.18420/SE2020_13

Haben Sie fehlerhafte Angaben entdeckt? Sagen Sie uns Bescheid: Feedback abschicken

Mehr Information

DOI: 10.18420/SE2020_13
ISBN: 978-3-88579-694-7
ISSN: 1617-5468
Datum: 2020
Sprache: en (en)
Typ: Text/Conference Paper

Keywords

  • Security-by-design
  • Security compliance
  • Data Flow Diagram (DFD)
  • Model-to-Model Transformation (M2M)
Sammlungen
  • P300 - Software Engineering 2020 [70]

Zur Langanzeige


Über uns | FAQ | Hilfe | Impressum | Datenschutz

Gesellschaft für Informatik e.V. (GI), Kontakt: Geschäftsstelle der GI
Diese Digital Library basiert auf DSpace.

 

 


Über uns | FAQ | Hilfe | Impressum | Datenschutz

Gesellschaft für Informatik e.V. (GI), Kontakt: Geschäftsstelle der GI
Diese Digital Library basiert auf DSpace.