Authors
Bastian Best, Jan Jurjens, Bashar Nuseibeh
Publication date
2007/5/20
Conference
29th International Conference on Software Engineering (ICSE'07)
Pages
581-590
Publisher
IEEE
Description
Given the explosive growth of digitally stored information in modern enterprises, distributed information systems together with search engines are increasingly used in companies. By enabling the user to search all relevant information sources with one single query, however, crucial risks concerning information security arise. In order to make these applications secure, it is not sufficient to penetrate- and-patch past system development, but security analysis has to be an integral part of the system design process for such distributed information systems. This work presents the experiences and results of the security analysis of a search engine in the intranet of a German car manufacturer, by making use of an approach to model-based security engineering that is based on the UML extension UMLsec. The focus lies on the application's single-sign-on-mechanism, which was analyzed using the UMLsec method and tools …
Total citations
200720082009201020112012201320142015201620172018201920202021202220232024491571169101037343351
Scholar articles
B Best, J Jurjens, B Nuseibeh - 29th International Conference on Software Engineering …, 2007