Passer à la navigation principale Passer à la recherche Passer au contenu principal

Using requirements engineering in an automatic security policy derivation process

  • Mariem Graa
  • , Nora Cuppens-Boulahia
  • , Fabien Autrel
  • , Hanieh Azkia
  • , Frédéric Cuppens
  • , Gouenou Coatrieux
  • , Ana Cavalli
  • , Amel Mammar
  • ENST Bretagne
  • Telecom Sudparis

Résultats de recherche: Le chapitre dans un livre, un rapport, une anthologie ou une collectionContribution à une conférenceRevue par des pairs

Résumé

Traditionally, a security policy is defined from an informal set of requirements, generally written using natural language. It is then difficult to appreciate the compatibility degree of the manually generated security policy with the informal requirements definition. The idea of this paper is to automate the process of deriving the formal security policy, using a more structured specification of the security objectives issued by the administrator of the information system to be secured. We chose the goal-oriented methodology KAOS to express the functional objectives, then based on the results of a risk analysis, we integrate the security objectives to the obtained KAOS framework. Finally, through a process of transformation applied to this structured security objectives specification, we automatically generate the corresponding security policy. This policy is consistent with the access control model OrBAC (Organization Access Control).

langue originaleAnglais
titreData Privacy Management and Autonomous Spontaneous Security - 6th International Workshop, DPM 2011, and 4th International Workshop, SETOP 2011, Revised Selected Papers
EditeurSpringer Verlag
Pages155-172
Nombre de pages18
ISBN (imprimé)9783642288784
Les DOIs
étatPublié - 1 janv. 2012
Evénement6th International Workshop on Data Privacy Management, DPM 2011 and 4th SETOP International Workshop on Autonomous and Spontaneous Security, SETOP 2011 - Leuven, Belgique
Durée: 15 sept. 201116 sept. 2011

Série de publications

NomLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume7122 LNCS
ISSN (imprimé)0302-9743
ISSN (Electronique)1611-3349

Une conférence

Une conférence6th International Workshop on Data Privacy Management, DPM 2011 and 4th SETOP International Workshop on Autonomous and Spontaneous Security, SETOP 2011
Pays/TerritoireBelgique
La villeLeuven
période15/09/1116/09/11

Empreinte digitale

Examiner les sujets de recherche de « Using requirements engineering in an automatic security policy derivation process ». Ensemble, ils forment une empreinte digitale unique.

Contient cette citation