• DocumentCode
    2696185
  • Title

    Evaluating fault tolerance in security requirements of web services

  • Author

    Mougouei, Davoud ; Rahman, Wan Nurhayati Wan Ab ; Almasi, Mohammad Moein

  • Author_Institution
    Fac. of Comput. Sci. & Inf. Technol., Univ. Putra Malaysia, Serdang, Malaysia
  • fYear
    2012
  • fDate
    26-28 June 2012
  • Firstpage
    111
  • Lastpage
    116
  • Abstract
    It is impossible to identify all of the internal and external security faults (vulnerabilities and threats) during the security analysis of web services. Hence, complete fault prevention would be impossible and consequently a security failure may occur within the system. To avoid security failures, we need to provide a measurable level of fault tolerance in the security requirements of target web service. Although there are some approaches toward assessing the security of web services but still there is no well-defined evaluation model for security improvement specifically during the requirement engineering phase. This paper introduces a measurement model for evaluating the degree of fault tolerance (FTMM) in security requirements of web services by explicitly factoring the mitigation techniques into the evaluation process which eventually contributes to required level of fault tolerance in security requirements. Our approach evaluates overall tolerance of the target service in the presence of the security faults through evaluating the computational security requirement model (SRM) of the service. We measure fault tolerance of the target web service by taking into consideration the cost, technical ability, impact and flexibility of the security goals established to mitigate the security faults.
  • Keywords
    Web services; security of data; software fault tolerance; Web services; computational security requirement; external security faults; fault tolerance evaluation; internal security faults; security failure; security requirements; Discrete Fourier transforms; Equations; Fault tolerance; Fault tolerant systems; Mathematical model; Security; Web services; security fault; threat; vulnerability; web service;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Cyber Security, Cyber Warfare and Digital Forensic (CyberSec), 2012 International Conference on
  • Conference_Location
    Kuala Lumpur
  • Print_ISBN
    978-1-4673-1425-1
  • Type

    conf

  • DOI
    10.1109/CyberSec.2012.6246125
  • Filename
    6246125