Authors
Anas Motii, Brahim Hamid, Agnes Lanusse, Jean-Michel Bruel
Publication date
2015/7/8
Book
Proceedings of the 20th European Conference on Pattern Languages of Programs
Pages
1-17
Description
Security pattern-based system and software engineering (PBSE) approaches aim at building secure software and systems by capturing and reusing artifacts that encapsulate security expert's knowledge called security patterns. In this context, security patterns are selected by developers based on security requirements. On the other hand, security risk management is an iterative approach that consists of: (1) a risk assessment activity for identifying, analyzing and evaluating security risks and (2) a risk treatment activity to mitigate these risks which result in issuing security requirements. Hence, risk management and security PBSE can be used together. In this context, this paper aims at guiding the selection of security patterns in security PBSE based on security risk management results and pattern classification. For illustration purposes, we consider an example of a SCADA (Supervisory Control And Data Acquisition …
Total citations
201620172018201920202021202220232024243414312
Scholar articles
A Motii, B Hamid, A Lanusse, JM Bruel - Proceedings of the 20th European Conference on …, 2015