A security engineering process for systems of systems using security patterns

SysCon(2014)

引用 9|浏览3
暂无评分
摘要
The creation of secure systems of systems is a complex process. A large variety of security expertise and knowledge specific for application domains is required. This is even more important if systems of systems span different application domains. Then, security threats specific to different application-domains need to be considered. One example is integrated systems for industrial production processes that interface office domains with supply chain management systems as well as a production environment. Such integrated systems of systems can perform very efficient and economic processes. However, due to the many and different domain-specific security requirements and threats security engineering needs to support requirements specification and architecture design very early in the development process in order to ensure resilience and safety of the complete system. Working with different domains implies that properties and its functionalities are specific and the engineering process used for modeling and designing the complete system has to be able to work in this context, covering all the possibilities and allowing the use of trusted solutions that are compatible with the ones of different domains. We present in this paper a security engineering process for creating secure systems of systems that cover the necessities presented above by using a series of security artifacts that contain the domain-specific security information (in terms of security properties) and provide security solutions in the form of security patterns. These patterns contain the definition of the software/hardware elements used for providing the required solution and the information of related patterns for different domains, which provides a very helpful functionality for creating a system of systems.
更多
查看译文
关键词
formal specification,security of data,software architecture,systems analysis,application domains,architecture design,complex process,development process,domain-specific security requirements,economic processes,hardware elements,industrial production processes,integrated systems of systems,interface office domains,knowledge specific,production environment,requirements specification,secure systems of systems,security artifacts,security engineering process,security expertise,security patterns,security properties,security solutions,security threats,software elements,supply chain management systems,system design,system modeling,system safety,trusted solutions,model-based systems engineering,research in systems engineering,engineering systems of systems,security,modeling,production,computer architecture,knowledge engineering,unified modeling language
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要