• DocumentCode
    2180784
  • Title

    RUPSec: extending business modeling and requirements disciplines of RUP for developing secure systems

  • Author

    Jaferian, Pooya ; Elahi, Golnaz ; Shirazi, Mohammad Reza Ayatollahzadeh ; Sadeghian, Babak

  • Author_Institution
    Dept. of Comput. Eng. & Inf. Technol., Amirkabir Univ. of Technol., Tehran, Iran
  • fYear
    2005
  • fDate
    30 Aug.-3 Sept. 2005
  • Firstpage
    232
  • Lastpage
    239
  • Abstract
    Nowadays, one of the main challenges facing computer systems is increasing attacks and security threats against them. Therefore, capturing, analyzing, designing, developing and testing of security requirements have became an important issue in development of security-critical computing systems, such as banking, military and e-commerce systems. For developing every system, a process model is chosen. The rational unified process (RUP) is one of the most popular and complete process models which has been used by developers in recent years. Our study and analysis has shown that RUP should be extended for developing security-critical systems. In this paper, we report our work on extending business modeling and requirements disciplines of RUP for developing secure systems. We call this extended version of RUP as RUPSec. The proposed extensions in RUPSec are adding and integrating a number of activities, roles, and artifacts to RUP in order to capture, document and model threats and security requirements.
  • Keywords
    corporate modelling; safety-critical software; security of data; RUPSec; banking system; business modeling; computer system; e-commerce system; military system; process model; rational unified process; security attack; security requirement; security threat; security-critical computing system; Banking; Computer security; ISO standards; Information security; Information technology; Military computing; Programming; Software engineering; Software testing; System testing;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Software Engineering and Advanced Applications, 2005. 31st EUROMICRO Conference on
  • Print_ISBN
    0-7695-2431-1
  • Type

    conf

  • DOI
    10.1109/EUROMICRO.2005.51
  • Filename
    1517747