Enforcing a security pattern in stakeholder goal models

  • Authors:
  • Yijun Yu;Haruhiko Kaiya;Hironori Washizaki;Yingfei Xiong;Zhenjiang Hu;Nobukazu Yoshioka

  • Affiliations:
  • The Open University, Milton Keynes, United Kngdm;Shinshu University, Nagano City, Japan;Waseda University, Tokyo, Japan;University of Tokyo, Tokyo, Japan;NII, Tokyo, Japan;NII, Tokyo, Japan

  • Venue:
  • Proceedings of the 4th ACM workshop on Quality of protection
  • Year:
  • 2008

Quantified Score

Hi-index 0.01

Visualization

Abstract

Patterns are useful knowledge about recurring problems and solutions. Detecting a security problem using patterns in requirements models may lead to its early solution. In order to facilitate early detection and resolution of security problems, in this paper, we formally describe a role-based access control (RBAC) as a pattern that may occur in stakeholder requirements models. We also implemented in our goal-oriented modeling tool the formally described pattern using model-driven queries and transformations. Applied to a number of requirements models published in literature, the tool automates the detection and resolution of the security pattern in several goal-oriented stakeholder requirements.