DocumentCode :
2088521
Title :
Security and privacy requirements analysis within a social setting
Author :
Liu, Lin ; Yu, Eric ; Mylopoulos, John
Author_Institution :
Dept. of Comput. Sci., Toronto Univ., Ont., Canada
fYear :
2003
fDate :
8-12 Sept. 2003
Firstpage :
151
Lastpage :
161
Abstract :
Security issues for software systems ultimately concern relationships among social actors stakeholders, system users, potential attackers - and the software acting on their behalf. We propose a methodological framework for dealing with security and privacy requirements based on i*, an agent-oriented requirements modeling language. The framework supports a set of analysis techniques. In particular, attacker analysis helps identify potential system abusers and their malicious intents. Dependency vulnerability analysis helps detect vulnerabilities in terms of organizational relationships among stakeholders. Countermeasure analysis supports the dynamic decision-making process of defensive system players in addressing vulnerabilities and threats. Finally, access control analysis bridges the gap between security requirement models and security implementation models. The framework is illustrated with an example involving security and privacy concerns in the design of agent-based health information systems. In addition, we discuss model evaluation techniques, including qualitative goal model analysis and property verification techniques based on model checking.
Keywords :
data privacy; decision making; formal verification; security of data; systems analysis; access control analysis; agent based health information systems; agent oriented requirements modeling language; decision-making process; model checking; model evaluation techniques; potential attackers; qualitative goal model analysis; security issues; social actors stakeholders; software systems; system users; verification techniques; vulnerability analysis; Privacy;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Requirements Engineering Conference, 2003. Proceedings. 11th IEEE International
ISSN :
1090-705X
Print_ISBN :
0-7695-1980-6
Type :
conf
DOI :
10.1109/ICRE.2003.1232746
Filename :
1232746
Link To Document :
بازگشت