Title :
An Agent-Based System to Support Assurance of Security Requirements
Author :
Ouedraogo, Moussa ; Mouratidis, Haralambos ; Khadraoui, Djamel ; Dubois, Eric
Author_Institution :
Public Res. Center Henri Tudor, Kirchberg, Luxembourg
Abstract :
Current approaches to evaluating security assurance either focus on the software development stage or at the end product software. However, most often, it is after the deployment or implementation phase that specified security requirements may be violated. This may be due to improper deployment of the security measures, environmental hazards or to the fact that the assumptions under which the security requirements have been specified have become invalid. As such, this paper proposes an approach (supported by a system) which will complement security requirements engineering methodologies by gathering continuous evidence to inform on whether the security requirements elucidated during system development stage have been correctly implemented and as such, they can be relied upon to effectively protect system assets at runtime. We use Secure Tropos methodology to highlight the security assurance case and elicit the features of our security assurance evaluation system. We further depict the security assurance evaluation through an example based on firewalls configurations.
Keywords :
formal specification; formal verification; multi-agent systems; security of data; software performance evaluation; agent based system; secure tropos methodology; security assurance evaluation system; security requirements engineering methodology; software development stage; Hazards; Information security; Information systems; Information technology; Multiagent systems; Programming; Protection; Reliability engineering; Software engineering; Synthetic aperture sonar; Secure Tropos; Security assurance; Security requirements; multi-agents systems; security verification;
Conference_Titel :
Secure Software Integration and Reliability Improvement (SSIRI), 2010 Fourth International Conference on
Conference_Location :
Singapore
Print_ISBN :
978-1-4244-7435-6
DOI :
10.1109/SSIRI.2010.32