Model based security risk analysis for web applications: the CORAS approach

  • Authors:
  • T. Dimitrakos;B. Ritchie;D. Raptis;K. Stølen

  • Affiliations:
  • Central Laboratory of the Research Councils, UK;Central Laboratory of the Research Councils, UK;Intracom S.A, Greece;SINTEF Group, Norway

  • Venue:
  • EuroWeb'02 Proceedings of the 2002 international conference on EuroWeb
  • Year:
  • 2002

Quantified Score

Hi-index 0.00

Visualization

Abstract

Security evaluation and security assurance are important aspects of trust in e-business. CORAS is a European project which is developing a tool-supported framework for precise, unambiguous, and efficient risk assessment of security critical systems. The framework is obtained through adapting, refining, extending, and combining methods for risk analysis of critical systems and semiformal modelling methods. In this paper we provide an overview of the CORAS framework for model-based risk assessment, emphasising its application on Web-enabled B2C e-commerce services and the meta-data based deployment model underpinning the CORAS extensible platform for tool inclusion.