Security Design Based on Social Modeling

Computer Software and Applications Conference, 2006. COMPSAC '06. 30th Annual International(2006)

引用 11|浏览0
暂无评分
摘要
Design for security is extremely complicated due to the unique nature of the issue. It requires a thorough understanding about the social setting of the security system. To obtain such understanding, sensible steps to take include identifying the players involved in the system, recognizing their personal preferences, agenda and power in relation to other players, identifying the assets being protected, the vulnerable points at which the systems may fail when attacked. Equally important is to taking rationale steps to predict most likely attackers, knowing their possible motivations, and capabilities enabled by latest the technologies and resource occupations. Only based on integrated analysis on both sides, rationale, informative and efficient tradeoffs on security can be made. Unfortunately, current system development practices treat design decisions on security in an ad-hoc way, often as an afterthought. This paper proposes to use social modeling concepts to analyze the business and organizational context of systems with regard to security. The main concepts used are actor, role, agent and goal, task, and resource dependencies between actors. The approach encompasses several analysis steps on the functional and non-functional requirements in relevance to security, thus integrating security into the system design process from the outset
更多
查看译文
关键词
security system,resource occupation,nonfunctional requirements,design decision,rationale step,analysis step,security design,resource dependencies,integrated analysis,system design process,multi-agent systems,social modeling concept,i* framework,current system development practice,social modeling,software engineering,functional requirements,resource dependency,security of data,system design,non functional requirement,multi agent systems
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要