• DocumentCode
    2831187
  • Title

    An Ontological Interface for Software Developers to Select Security Patterns

  • Author

    El Khoury, P. ; Mokhtari, Amine ; Coquery, Emmanuel ; Hacid, Mohand-Said

  • Author_Institution
    SAP Res. Security & Trust, Lyon
  • fYear
    2008
  • fDate
    1-5 Sept. 2008
  • Firstpage
    297
  • Lastpage
    301
  • Abstract
    In the software development lifecycle, security expertise is one common missing quality that needs to be addressed on a stronger footing, by taking advantage of the scaling effect of security patterns. Security patterns capture security experts´ knowledge for a given security problem. Hence, they are produced by experts in security and consumed by novice security users, such as software developers. In this paper we present an ontology based approach to find an eligible set of security patterns requested by software developers. We adopt the formal description of security properties presented in the Serenity EU project for defining our ground security requirements. We distinguish between two profiles for software developers and define a corresponding ontological interface. This ontological interface contains a mapping between security requirements from one side and threat models, security bugs, security errors on another side taking into consideration their contexts of applicability. We describe the current status of this work in progress where results are quite promising.
  • Keywords
    expert systems; ontologies (artificial intelligence); security of data; software engineering; ontological interface; security expertise knowledge; security pattern; software development lifecycle; Application software; Computer bugs; Context modeling; Data security; Databases; Expert systems; Ontologies; Packaging; Programming; Software quality; Ontology; Profiles; Security Patterns;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Database and Expert Systems Application, 2008. DEXA '08. 19th International Workshop on
  • Conference_Location
    Turin
  • ISSN
    1529-4188
  • Print_ISBN
    978-0-7695-3299-8
  • Type

    conf

  • DOI
    10.1109/DEXA.2008.110
  • Filename
    4624732