Nothing Special   »   [go: up one dir, main page]

skip to main content
10.1109/ECBS.2009.17guideproceedingsArticle/Chapter ViewAbstractPublication PagesConference Proceedingsacm-pubtype
Article

Software Architectural Design Meets Security Engineering

Published: 14 April 2009 Publication History

Abstract

Security requirements strongly influence the architectural design of complex IT systems in a similar way as other non-functional requirements. Both security engineering as well as software engineering provide methods to deal with such requirements. However, there is still a critical gap concerning the integration of the methods of these separate fields. In this paper we close this gap with respect to security requirements by proposing a method that combines software engineering approaches with state-of-the-art security engineering principles. This method establishes an explicit alignment between the non-functional goal, the principles in the field of security engineering, and the implementation of a security architecture. The method aims at designing a system's security architecture based on a small, precisely defined, and application-specific trusted computing base. We illustrate this method by means of a case study which describes distributed enterprise resource planning systems using web services to implement business processes across company boundaries.

Cited By

View all
  • (2011)Problem-solution mapping for forward and reengineering on architectural levelProceedings of the 12th International Workshop on Principles of Software Evolution and the 7th annual ERCIM Workshop on Software Evolution10.1145/2024445.2024466(106-115)Online publication date: 5-Sep-2011
  • (2010)Impact evaluation for quality-oriented architectural decisions regarding evolvabilityProceedings of the 4th European conference on Software architecture10.5555/1887899.1887916(182-197)Online publication date: 23-Aug-2010

Recommendations

Comments

Please enable JavaScript to view thecomments powered by Disqus.

Information & Contributors

Information

Published In

cover image Guide Proceedings
ECBS '09: Proceedings of the 2009 16th Annual IEEE International Conference and Workshop on the Engineering of Computer Based Systems
April 2009
323 pages
ISBN:9780769536026

Publisher

IEEE Computer Society

United States

Publication History

Published: 14 April 2009

Author Tags

  1. design method
  2. non-functional requirements
  3. quality attributes
  4. security engineering
  5. security models
  6. security policies
  7. security requirements
  8. software architecture

Qualifiers

  • Article

Contributors

Other Metrics

Bibliometrics & Citations

Bibliometrics

Article Metrics

  • Downloads (Last 12 months)0
  • Downloads (Last 6 weeks)0
Reflects downloads up to 13 Nov 2024

Other Metrics

Citations

Cited By

View all
  • (2011)Problem-solution mapping for forward and reengineering on architectural levelProceedings of the 12th International Workshop on Principles of Software Evolution and the 7th annual ERCIM Workshop on Software Evolution10.1145/2024445.2024466(106-115)Online publication date: 5-Sep-2011
  • (2010)Impact evaluation for quality-oriented architectural decisions regarding evolvabilityProceedings of the 4th European conference on Software architecture10.5555/1887899.1887916(182-197)Online publication date: 23-Aug-2010

View Options

View options

Media

Figures

Other

Tables

Share

Share

Share this Publication link

Share on social media