Security engineering using problem frames

  • Authors:
  • Denis Hatebur;Maritta Heisel;Holger Schmidt

  • Affiliations:
  • Institut für technische Systeme GmbH, Germany;Faculty of Engineering, Department of Computer Science, Workgroup Software Engineering, University Duisburg-Essen, Germany;Faculty of Engineering, Department of Computer Science, Workgroup Software Engineering, University Duisburg-Essen, Germany

  • Venue:
  • ETRICS'06 Proceedings of the 2006 international conference on Emerging Trends in Information and Communication Security
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

We present a method for security engineering, which is based on two special kinds of problem frames that serve to structure, characterize, analyze, and finally solve software development problems in the area of software and system security. Both kinds of problem frames constitute patterns for representing security problems, variants of which occur frequently in practice. We present security problem frames, which are instantiated in the initial step of our method. They explicitly distinguish security problems from their solutions. To prepare the solution of the security problems in the next step, we employ concretized security problem frames capturing known approaches to achieve security. Finally, the last step of our method results in a specification of the system to be implemented given by concrete security mechanisms and instantiated generic sequence diagrams. We illustrate our approach by the example of a secure remote display system.