• DocumentCode
    3687795
  • Title

    Towards a model-driven based security framework

  • Author

    Rouwaida Abdallah;Nataliya Yakymets;Agnes Lanusse

  • Author_Institution
    CEA, LIST, Laboratory of Model Driven Engineering for Embedded Systems, Gif-sur-Yvette Cedex, France
  • fYear
    2015
  • Firstpage
    639
  • Lastpage
    645
  • Abstract
    In this paper, we propose a model-driven framework for security analysis. We present a security analysis process that begins from the design phase of the system architecture then allows performing several security analysis methods. Our approach presents mainly two advantages: First, it allows the traceability of the security analysis methods with the system architecture. Second, this framework can include several security analysis methods. Moreover it allows information reuse which is complicated when we use separate methods dedicated tools. Thus, we can have more consistent and accurate security analysis results for a system. We chose to implement two methods: A qualitative method named EBIOS which is simple and helps to identify areas of focus within the system. Then, to get more accurate results, we implement a quantitative method, the Attack trees. Attack trees can be automatically generated from the Ebios analysis phase and can be completed later on to get more specific results.
  • Keywords
    "Security","Unified modeling language","Analytical models","Systems architecture","Risk analysis","Software","Computational modeling"
  • Publisher
    ieee
  • Conference_Titel
    Model-Driven Engineering and Software Development (MODELSWARD), 2015 3rd International Conference on
  • Type

    conf

  • Filename
    7323180