• DocumentCode
    2231910
  • Title

    Analyzing Security Interoperability during Component Integration

  • Author

    Oladimeji, Ebenezer A. ; Chung, Lawrence

  • Author_Institution
    Archit. & eServices, Verizon Commun., Irving, TX
  • fYear
    2006
  • fDate
    10-12 July 2006
  • Firstpage
    121
  • Lastpage
    129
  • Abstract
    Developing large software systems by integrating components has a great potential to reduce costs and time to market. However, it also poses serious threats to the nonfunctional aspects of the composed system. One such problem is how to build secure composite system from components which may or may not be individually secure. A systematic approach for determining interoperability of components from a security standpoint and unifying the security features, policies and implementation mechanisms of components is needful. This paper presents a goal-oriented and model-driven approach to analyzing the security features of components to determine interoperability and a guideline for integrating them to fulfil the security goals of the composite system. The proposed analysis procedure leads to discovery of some classes of security interoperability conflicts which helps to determine whether or not the components should be used together. We provide an empirical study by applying the proposed approach to integrate two components by unifying the security features of the components to satisfice the security goals of a student and seminar information system
  • Keywords
    object-oriented programming; open systems; security of data; software engineering; goal-oriented approach; large software system development; model-driven approach; security interoperability conflict; software component integration; software component interoperability; software cost reduction; software time to market reduction; Communication system security; Computer architecture; Computer science; Costs; Guidelines; Information security; Interconnected systems; Seminars; Software systems; Time to market;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer and Information Science, 2006 and 2006 1st IEEE/ACIS International Workshop on Component-Based Software Engineering, Software Architecture and Reuse. ICIS-COMSAR 2006. 5th IEEE/ACIS International Conference on
  • Conference_Location
    Honolulu, HI
  • Print_ISBN
    0-7695-2613-6
  • Type

    conf

  • DOI
    10.1109/ICIS-COMSAR.2006.22
  • Filename
    1651980