• DocumentCode
    2413173
  • Title

    Integrating Formal Analysis and Design to Preserve Security Properties

  • Author

    Hassan, Rohayanti ; Bohner, S. ; El-Kassas, S. ; Hinchey, Mike

  • Author_Institution
    Dept. of Comput. Sci., Virginia Tech., Blacksburg, VA
  • fYear
    2009
  • fDate
    5-8 Jan. 2009
  • Firstpage
    1
  • Lastpage
    10
  • Abstract
    The use of formal methods has long been advocated in the development of secure systems. Yet, methods for deriving design from requirements that guarantee retention of the intended security properties remain largely unrealized on a repeatable and consistent basis. We present the FADES (Formal Analysis and Design approach for Engineering Security) that integrates KAOS (Knowledge Acquisition in automated Specifications) with the B specification language to derive security design specifications and further implementation from security requirements. We demonstrate the capability of the approach to handle changes to security requirements by introducing corrective changes to the security requirements of a case study, the spy network system. The objective is to bridge the gap between formal requirements and design for security requirements. Our initial results show promise with FADES in preserving security properties and detecting security vulnerabilities early during requirements. Encouraged by these, we are more quantitatively assessing the FADES capabilities.
  • Keywords
    knowledge acquisition; security of data; specification languages; B specification language; automated specifications; engineering security; formal analysis; formal methods; knowledge acquisition; secure systems; security properties; spy network system; Bridges; Computer science; Computer security; Costs; Design engineering; Design methodology; Information security; Knowledge acquisition; Knowledge engineering; Specification languages;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    System Sciences, 2009. HICSS '09. 42nd Hawaii International Conference on
  • Conference_Location
    Big Island, HI
  • ISSN
    1530-1605
  • Print_ISBN
    978-0-7695-3450-3
  • Type

    conf

  • DOI
    10.1109/HICSS.2009.267
  • Filename
    4755412