Authors
Charles Haley, Robin Laney, Jonathan Moffett, Bashar Nuseibeh
Publication date
2008/1/31
Journal
IEEE Transactions on Software Engineering
Volume
34
Issue
1
Pages
133-153
Publisher
IEEE
Description
This paper presents a framework for security requirements elicitation and analysis. The framework is based on constructing a context for the system, representing security requirements as constraints, and developing satisfaction arguments for the security requirements. The system context is described using a problem-oriented notation, then is validated against the security requirements through construction of a satisfaction argument. The satisfaction argument consists of two parts: a formal argument that the system can meet its security requirements and a structured informal argument supporting the assumptions expressed in the formal argument. The construction of the satisfaction argument may fail, revealing either that the security requirement cannot be satisfied in the context or that the context does not contain sufficient information to develop the argument. In this case, designers and architects are asked to …
Total citations
20072008200920102011201220132014201520162017201820192020202120222023202452030394646444344325244233625252211
Scholar articles
C Haley, R Laney, J Moffett, B Nuseibeh - IEEE Transactions on Software Engineering, 2008