• DocumentCode
    2703975
  • Title

    A Service-Oriented Framework for Quantitative Security Analysis of Software Architectures

  • Author

    Liu, Yanguo ; Traore, Issa ; Hoole, Alexander M.

  • Author_Institution
    Dept. of Electr. & Comput. Eng., Univ. of Victoria, Victoria, BC
  • fYear
    2008
  • fDate
    9-12 Dec. 2008
  • Firstpage
    1231
  • Lastpage
    1238
  • Abstract
    Software systems today often run in malicious environments in which attacks or intrusions are quite common. This situation has brought security concerns into the development of software systems. Generally, software services are expected not only to satisfy functional requirements but also to be resistant to malicious attacks. Software attackability is defined as the likelihood that an attack on a software system will succeed. In this paper, we present a service-oriented framework to analyze attackability of software systems. More specifically, we propose a User System Interaction Effect (USIE) model that can be used systematically to derive and analyze security concerns from service-oriented software architectures. Many aspects of the model derivation and analysis can be automated, which limit the amount of user involvement, and thereby reduce the subjectivity underlying typical security risk analysis process. The model can be used as a foundation for quantitative analysis of software services from different security perspectives.
  • Keywords
    Web services; human computer interaction; risk analysis; security of data; software architecture; software quality; malicious software attackability; quantitative security analysis; security risk analysis process; service-oriented software architecture; software quality attribute; software system; user system interaction effect model; Computer architecture; Computer crime; Computer security; Programming; Risk analysis; Service oriented architecture; Software architecture; Software measurement; Software quality; Software systems; Architecture Analysis; Security Engineering; Service-oriented Development; Software Attackability; Software Metrics;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Asia-Pacific Services Computing Conference, 2008. APSCC '08. IEEE
  • Conference_Location
    Yilan
  • Print_ISBN
    978-0-7695-3473-2
  • Electronic_ISBN
    978-0-7695-3473-2
  • Type

    conf

  • DOI
    10.1109/APSCC.2008.17
  • Filename
    4780848