Swinburne
Browse

Specifying security goals of component based systems: An end-user perspective

Download (186.28 kB)
conference contribution
posted on 2024-07-26, 14:11 authored by Khaled M. Khan, Jun HanJun Han
This paper treats security from a software engineering point of view. Security issues of software components are usually handled at the two levels of development abstractions: by the security experts during the component design, and by the software engineers during the composition of an application system. Security experts identify the threats of the component, define the security policies and functions. On the other hand, the software engineers are more interested in the compositional impact and conformity of the security properties designed and implemented by the security experts. This paper identifies a third level of abstraction: security from the end-users' perspective. This paper argues that the end-users of the system should know the specific security objectives actually achieved at the system-level. This paper makes the following three specific contributions in this regard: (i) a need for a separate view of security at the end-user level; (ii) the formulation of security goals; (iii) the derivation of security goals for automatic processing.

History

Available versions

PDF (Published version)

ISBN

769530915

Journal title

Proceedings - 7th International Conference on Composition-Based Software Systems, ICCBSS 2008

Conference name

7th International Conference on Composition-Based Software Systems, ICCBSS 2008

Pagination

8 pp

Publisher

IEEE

Copyright statement

Copyright © 2008 IEEE. The published version is reproduced in accordance with the copyright policy of the publisher. Personal use of this material is permitted. However, permission to reprint/republish this material for advertising or promotional purposes or for creating new collective works for resale or redistribution to servers or lists, or to reuse any copyrighted component of this work in other works must be obtained from the IEEE.

Language

eng

Usage metrics

    Publications

    Categories

    No categories selected

    Keywords

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC