Title :
A method for modeling and analyzing the security attributes of service-oriented software system
Author :
Li, Liu ; Chunlei, Wang ; Liang, Ming
Author_Institution :
Sci. & Technol. on Inf. Syst. Security Lab., Beijing, China
Abstract :
In Service Oriented Architecture (SOA), software is implemented through a series of services and the business processes composed of services which introduce potential security problems. These security problems appeared in SOA software applications usually lead information systems and their business processes to risks. Similar to traditional quality of service (QoS) attributes such as reliability and robustness, security is one of the most important attributes of software system. In this paper, the method for modeling and analyzing the security attributes of SOA software system is investigated. Firstly, the service oriented computing model for security analysis is constructed, which characterizes service computing paradigm and related security attributes, and can be used for establishing service oriented software security metric system. Secondly, the service attack path is analyzed based upon the service oriented computing model. Finally, the effectiveness of the model and the analysis method is validated through case studies.
Keywords :
information systems; security of data; service-oriented architecture; software metrics; software reliability; SOA software applications; information systems; quality of service attributes; reliability; robustness; security attributes; security problems; service attack path; service computing paradigm; service oriented architecture; service oriented software security metric system; Analytical models; Computational modeling; Information systems; Irrigation; Laboratories; Security; Software; security analysis; security model; service oriented architecture; software security;
Conference_Titel :
Computer Science and Network Technology (ICCSNT), 2011 International Conference on
Conference_Location :
Harbin
Print_ISBN :
978-1-4577-1586-0
DOI :
10.1109/ICCSNT.2011.6182044