A general method for assessment of security in complex services

  • Authors:
  • Leanid Krautsevich;Fabio Martinelli;Artsiom Yautsiukhin

  • Affiliations:
  • Department of Computer Science, University of Pisa, Pisa, Italy;Istituto di Informatica e Telematica, Consiglio Nazionale delle Ricerche, Pisa, Italy;Istituto di Informatica e Telematica, Consiglio Nazionale delle Ricerche, Pisa, Italy

  • Venue:
  • ServiceWave'11 Proceedings of the 4th European conference on Towards a service-based internet
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

We focus on the assessment of the security of business processes. We assume that a business process is composed of abstract services, each of which has several concrete instantiations. Essential peculiarity of our method is that we express security metrics used for the evaluation of security properties as semirings. First, we consider primitive decomposition of the business process into a weighted graph which describes possible implementations of the business process. Second, we evaluate the security using semiring-based methods for graph analysis. Finally, we exploit semirings to describe the mapping between security metrics which is useful when different metrics are used for the evaluation of security properties of services.