Security-Critical System Development with Extended Use Cases

  • Authors:
  • G. Popp;J. Jürjens;G. Wimmel;R. Breu

  • Affiliations:
  • -;-;-;-

  • Venue:
  • APSEC '03 Proceedings of the Tenth Asia-Pacific Software Engineering Conference Software Engineering Conference
  • Year:
  • 2003

Quantified Score

Hi-index 0.00

Visualization

Abstract

Due to increasing interconnection, IT systems are confrontedwith more and more attacks. To address this problem,we have to consider security requirements from the beginningof the system development. In early phases of systemdevelopment, it is common to use a hybrid system viewwhich is based on an object oriented modeling of the applicationcore and the specification of use cases. In thispaper, we present an extension of this process for security-criticalsystems. We show a methodical approach for thedevelopment of security-critical systems and the modelingof security aspects in the application core with an extensionof the Unified Modeling Language for secure systems development,UMLsec. Furthermore, we introduce security usecases for the development of security aspects in conjunctionwith behavioral modeling.