DocumentCode :
1833442
Title :
Security Evaluation of Service-oriented Systems with an Extensible Knowledge Base
Author :
Jung, Christian ; Rudolph, Manuel ; Schwarz, Reinhard
Author_Institution :
Fraunhofer Inst. for Exp. Software Eng. (IESE), Kaiserslautern, Germany
fYear :
2011
fDate :
22-26 Aug. 2011
Firstpage :
698
Lastpage :
703
Abstract :
Service-oriented software architectures promise enhanced interoperability, reusability, and flexibility for the implementation of business processes. However, assuring the quality of SOA software is challenging due to the distributed, inhomogeneous, and often non-transparent nature of service building blocks. Especially security, which is an overarching quality concern of a system, poses a hard problem for quality assurance in a SOA context. We have developed SiSOA, a method for static security analysis of SOA systems based on reverse-engineering techniques to recover the software architecture and to extract security-related information from available system artifacts. In SiSOA, the extraction and aggregation of security facts is controlled by security rules stored in an extensible knowledge base. In this paper, we describe the structure of the SiSOA knowledge base, its underlying principles, and its role within the SiSOA methodology. We briefly survey our SiSOA prototype tool, and we illustrate the application of knowledge base rules with exemplary security scenarios.
Keywords :
knowledge based systems; open systems; program diagnostics; quality assurance; reverse engineering; security of data; service-oriented architecture; software quality; software reusability; SOA software quality; SiSOA; business processes; extensible knowledge base; knowledge base rules; quality assurance; reverse-engineering techniques; security evaluation; security-related information extraction; service building blocks; service-oriented software architectures; service-oriented systems; software flexibility; software interoperability; software reusability; static security analysis; system artifacts; IEEE Potentials; Knowledge based systems; Prototypes; Security; Service oriented architecture; Tagging; Security; architecture-centric software assessment; security evaluation; service-oriented architectures;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Availability, Reliability and Security (ARES), 2011 Sixth International Conference on
Conference_Location :
Vienna
Print_ISBN :
978-1-4577-0979-1
Electronic_ISBN :
978-0-7695-4485-4
Type :
conf
DOI :
10.1109/ARES.2011.109
Filename :
6046023
Link To Document :
بازگشت