| Towards an architectural treatment of software security: a connector-centric approach |
| Full text |
Pdf
(334 KB)
|
| Source
|
International Conference on Software Engineering
archive
Proceedings of the 2005 workshop on Software engineering for secure systems—building trustworthy applications
table of contents
St. Louis, Missouri
SESSION: Software Engineering for Secure Systems (SESS) --- Building Trustworthy Applications
table of contents
Pages: 1 - 7
Year of Publication: 2005
ISBN:1-59593-114-7
Also published in ...
|
|
Authors
|
|
Jie Ren
|
University of California, Irvine, Irvine, CA
|
|
Richard Taylor
|
University of California, Irvine, Irvine, CA
|
|
Paul Dourish
|
University of California, Irvine, Irvine, CA
|
|
David Redmiles
|
University of California, Irvine, Irvine, CA
|
|
| Publisher |
|
| Bibliometrics |
Downloads (6 Weeks): 10, Downloads (12 Months): 119, Citation Count: 1
|
|
|
ABSTRACT
Security is a very important concern for software architecture and software components. Previous modeling approaches provide insufficient support for an in-depth treatment of security. This paper argues for a more comprehensive treatment based on software connectors. Connectors provide a suitable vehicle to model, capture, and enforce security. Our approach models security principal, privilege, trust, and context of architectural constituents. Extending our existing architecture description language and support tools, our approach can facilitate describing the security characteristics of an architecture generating enabling infrastructure, and monitoring run-time conformance. Initial results of applying this approach are illustrated through a case study. The contribution of this research is a deeper and more comprehensive treatment of architectural security through software connectors.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
 |
1
|
|
 |
2
|
|
 |
3
|
|
| |
4
|
|
| |
5
|
Stephanie Bodoff , Eric Armstrong , Jennifer Ball , Debbie Bode Carson, The J2EE Tutorial, Second Edition, Addison-Wesley Longman Publishing Co., Inc., Boston, MA, 2004
|
| |
6
|
Clemm, G., Reschke, J., Sedlar, E., and Whitehead, J., Web Distributed Authoring and Versioning (Webdav) Access Control Protocol. RFC 3744, 2004.
|
| |
7
|
Cuesta, C. E., Romay, M. P., Fuente, P. D. L., and Barrio-Solorzano, M. Reflection-Based, Aspect-Oriented Software Architecture. in Proceedings of 1st European Workshop on Software Architecture, p.43--56, 2004.
|
 |
8
|
|
| |
9
|
|
| |
10
|
|
| |
11
|
Rogério de Paula , Xianghua Ding , Paul Dourish , Kari Nies , Ben Pillet , David F. Redmiles , Jie Ren , Jennifer A. Rode , Roberto Silva Filho, In the eye of the beholder: a visualization-based approach to information system security, International Journal of Human-Computer Studies, v.63 n.1-2, p.5-24, July 2005
[doi> 10.1016/j.ijhcs.2005.04.021]
|
 |
12
|
|
 |
13
|
|
| |
14
|
France, R., Ray, I., Georg, G., and Ghosh, S., Aspect-Oriented Approach to Early Design Modelling. IEE Proceedings-Software, 2004. 151(4): p. 173--185.
|
| |
15
|
|
 |
16
|
|
 |
17
|
|
| |
18
|
|
 |
19
|
|
 |
20
|
|
| |
21
|
|
 |
22
|
|
| |
23
|
|
| |
24
|
Ray, I., France, R., Li, N., and Georg, G., An Aspect-Based Approach to Modeling Access Control Concerns. Information and Software Technology, 2004. 46(9): p. 575--587.
|
| |
25
|
|
| |
26
|
|
| |
27
|
Sun, W. and Dai, Z. Aosam: A Formal Framework for Aspect-Oriented Software Architecture Specifications. in Proceedings of The 8th IASTED International Conference on Software Engineering and Applications, 2004.
|
| |
28
|
|
| |
29
|
Wing, J. M., A Call to Action: Look Beyond the Horizon. Security & Privacy Magazine, IEEE, 2003. 1(6): p. 62--67.
|
| |
30
|
Winslett, M. An Introduction to Trust Negotiation. in Proceedings of 1st International Conference on Trust Management, p.275--283, 2003.
|
|