Authors
Mazeiar Salehie, Liliana Pasquale, Inah Omoronyia, Raian Ali, Bashar Nuseibeh
Publication date
2012/9/24
Conference
2012 20th IEEE international requirements engineering conference (RE)
Pages
111-120
Publisher
IEEE
Description
Security is primarily concerned with protecting assets from harm. Identifying and evaluating assets are therefore key activities in any security engineering process - from modeling threats and attacks, discovering existing vulnerabilities, to selecting appropriate countermeasures. However, despite their crucial role, assets are often neglected during the development of secure software systems. Indeed, many systems are designed with fixed security boundaries and assumptions, without the possibility to adapt when assets change unexpectedly, new threats arise, or undiscovered vulnerabilities are revealed. To handle such changes, systems must be capable of dynamically enabling different security countermeasures. This paper promotes assets as first-class entities in engineering secure software systems. An asset model is related to requirements, expressed through a goal model, and the objectives of an attacker …
Total citations
201120122013201420152016201720182019202020212022202320241341917898710553
Scholar articles
M Salehie, L Pasquale, I Omoronyia, R Ali, B Nuseibeh - 2012 20th IEEE international requirements engineering …, 2012