DocumentCode
2458645
Title
Embedding Security Patterns into a Domain Model
Author
Solinas, Miguel ; Fernandez, Eduardo B. ; Antonelli, Leandro
Author_Institution
LAC, UNC Cordoba, Cordoba, Argentina
fYear
2009
fDate
Aug. 31 2009-Sept. 4 2009
Firstpage
176
Lastpage
180
Abstract
Incorporating security patterns at every stage of software development process is one of the most effective ways to build secure software. But how early in the software development process is it possible to apply security patterns? We present here an approach to define security requirements in order to identify security patterns in the very early stages of the software development process, we also show an experience with the method in a limited environment. We use natural language to express requirements (understandable to the Requirements Engineer as well as to the Domain Expert), from which it is possible to identify the security requirements and the corresponding security patterns. Language Extended Lexicon (LEL) and scenarios allow to understand, study, and model the security domain and to represent security patterns. To them we apply the Baseline Mentor Workbench (BMW) for deriving CRC (Class Responsibility Collaboration) cards that represent the security patterns and their contextual model domain. BMW is a tool to assist the domain expert during the requirements engineering stage.
Keywords
object-oriented programming; security of data; software tools; systems analysis; baseline mentor workbench; class responsibility collaboration card; contextual model domain; domain expert; language extended lexicon; requirements engineering; security pattern embedding; security requirement; software development process; Application software; Authorization; Cyclic redundancy check; Data security; Databases; Natural languages; Object oriented modeling; Pattern analysis; Programming; Software tools; CRC cards; object-oriented design; security patterns; security requirements;
fLanguage
English
Publisher
ieee
Conference_Titel
Database and Expert Systems Application, 2009. DEXA '09. 20th International Workshop on
Conference_Location
Linz
ISSN
1529-4188
Print_ISBN
978-0-7695-3763-4
Type
conf
DOI
10.1109/DEXA.2009.44
Filename
5337192
Link To Document