Composing patterns to construct secure systems

dc.contributor.authorRimba, Paulen_NZ
dc.contributor.authorZhu, Limingen_NZ
dc.contributor.authorBass, Lenen_NZ
dc.contributor.authorKuz, Ihoren_NZ
dc.contributor.authorReeves, Steveen_NZ
dc.coverage.spatialParis, Franceen_NZ
dc.date.accessioned2016-01-28T03:25:35Z
dc.date.available2015en_NZ
dc.date.available2016-01-28T03:25:35Z
dc.date.issued2015en_NZ
dc.description.abstractBuilding secure applications requires significant expertise. Secure platforms and security patterns have been proposed to alleviate this problem. However, correctly applying patterns to use platform features is still highly expertise-dependent. Patterns are informal and there is a gap between them and platform features. We propose the concept of reusable verified design fragments, which package security patterns and platform features and are verified to provide assurance about their security properties. Design fragments can be composed through four primitive tactics. The verification of the composed design against desired security properties is presented in an assurance case. We demonstrate our approach by securing a Continuous Deployment pipeline and show that the tactics are sufficient to compose design fragments into a secure system. Finally, we formally define composition tactics, which are intended to support the development of systems that are secure by construction.
dc.format.mimetypeapplication/pdf
dc.identifier.citationRimba, P., Zhu, L., Bass, L., Kuz, I., & Reeves, S. (2015). Composing patterns to construct secure systems. In Proc 11th European Dependable Computing Conference (pp. 213–224). Paris, France: IEEE. http://doi.org/10.1109/EDCC.2015.12en
dc.identifier.doi10.1109/EDCC.2015.12en_NZ
dc.identifier.isbn978-1-4673-9289-1en_NZ
dc.identifier.urihttps://hdl.handle.net/10289/9881
dc.language.isoen
dc.publisherIEEEen_NZ
dc.relation.isPartOfProc 11th European Dependable Computing Conferenceen_NZ
dc.rightsThis is an author’s accepted version of an article published in the 11th European Dependable Computing Conference. ©2015 IEEE. Personal use of this material is permitted. However, permission to reprint/republish this material for advertising or promotional purposes or for creating new collective works for resale or redistribution to servers or lists, or to reuse any copyrighted component of this work in other works must be obtained from the IEEE.
dc.sourceEDCC 2015en_NZ
dc.subjectsecurity
dc.subjectcomposition
dc.subjectassurance
dc.subjectcomputer science
dc.titleComposing patterns to construct secure systemsen_NZ
dc.typeConference Contribution
pubs.begin-page213
pubs.elements-id133363
pubs.end-page224
pubs.finish-date2015-09-11en_NZ
pubs.organisational-group/Waikato
pubs.organisational-group/Waikato/FCMS
pubs.organisational-group/Waikato/FCMS/Computer Science
pubs.start-date2015-09-07en_NZ
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
EDCC 2015 paper.pdf
Size:
1.22 MB
Format:
Adobe Portable Document Format
Description:
Accepted version
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
Deposit Agreement.txt
Size:
193 B
Format:
Unknown data format
Description: