• DocumentCode
    2745739
  • Title

    Model-Based Security Engineering of Distributed Information Systems Using UMLsec

  • Author

    Best, Bastian ; Jürjens, Jan ; Nuseibeh, Bashar

  • Author_Institution
    BMW Group, Munich
  • fYear
    2007
  • fDate
    20-26 May 2007
  • Firstpage
    581
  • Lastpage
    590
  • Abstract
    Given the explosive growth of digitally stored information in modern enterprises, distributed information systems together with search engines are increasingly used in companies. By enabling the user to search all relevant information sources with one single query, however, crucial risks concerning information security arise. In order to make these applications secure, it is not sufficient to penetrate- and-patch past system development, but security analysis has to be an integral part of the system design process for such distributed information systems. This work presents the experiences and results of the security analysis of a search engine in the intranet of a German car manufacturer, by making use of an approach to model-based security engineering that is based on the UML extension UMLsec. The focus lies on the application´s single-sign-on-mechanism, which was analyzed using the UMLsec method and tools. Main results of the paper include afield report on the employment of the UMLsec method in an industrial context as well as indications on its benefits and limitations.
  • Keywords
    Unified Modeling Language; distributed processing; search engines; security of data; UML extension UMLsec; distributed information systems; model-based security engineering; search engines; Companies; Distributed information systems; Employment; Explosives; Information analysis; Information security; Search engines; System analysis and design; Unified modeling language; Virtual manufacturing;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Software Engineering, 2007. ICSE 2007. 29th International Conference on
  • Conference_Location
    Minneapolis, MN
  • ISSN
    0270-5257
  • Print_ISBN
    0-7695-2828-7
  • Type

    conf

  • DOI
    10.1109/ICSE.2007.55
  • Filename
    4222619