A security pattern classification based on Data integration - Université Clermont Auvergne Accéder directement au contenu
Chapitre D'ouvrage Année : 2018

A security pattern classification based on Data integration

Résumé

Security patterns are design patterns specialised to provide reusable and general solutions to recurring security problems. These patterns , which capture the strengths of different security approaches, are intended to make the design of maintainable and secure applications easier. The pattern community is continuously providing new security patterns (180 patterns are available at the moment). For a given problem, this growing pattern set along with their abstract presentations make the security pattern choice tedious, even for experts in software design. We contribute in this issue by presenting a method of security pattern classification based upon data extraction and integration. The pattern classification is semi-automatically inferred by means of a data-store integrating disparate publicly available security data. This classification exposes relationships among software attacks, weaknesses, security principles and security patterns. It expresses the pattern combinations that can counter a given attack. Besides the pattern classification, we show that the data-store can be used to generate Attack Defense Trees. In our context, these illustrate, for a given attack, its sub-attacks and the related defenses given under the form of security pattern combinations. Such trees make the pattern classification more readable even for beginners in security patterns. Finally, we evaluate on 25 human subjects the benefits of using Attack Defense Trees and a classification established for Web applications, which covers 215 attacks, 136 software weaknesses, 66 security principles and 26 security patterns.
Fichier principal
Vignette du fichier
documentv2.pdf (633.96 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01868235 , version 1 (05-09-2018)

Identifiants

Citer

Sébastien Salva, Loukmen Regainia. A security pattern classification based on Data integration. Paolo Mori, Steven Furnell, Olivier Camp. Information Systems Security and Privacy, 867, Springer, pp.105-129, 2018, Communications in Computer and Information Science, ⟨10.1007/978-3-319-93354-2_6⟩. ⟨hal-01868235⟩
59 Consultations
310 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More