Skip to search boxSkip to navigationSkip to main content

Checking security compliance between models and code

  • Katja Tuma
    ,
  • ,
  • Daniel Struber
    ,
  • Riccardo Scandariato
    ,
  • Jan Juerjens
  • Vrije University Amsterdam
    ,
  • University of Koblenz
    ,
  • Radboud University Nijmegen
    ,
  • TU Hamburg-Harburg
Research Output:
Journal Article or Conference Article in Journal
Journal article
Peer-review

Open access

Publication Information

Output type

Research Output:
Journal Article or Conference Article in Journal
Journal article
Peer-review

Original language

English

Pages from-to (Number of pages)

Pages 273–296

Journal (Volume, Issue Number)

Software and Systems Modeling (Volume 22)

Publication milestones

  • Published - 2023

Publication status

Published - 2023

ISSN

1619-1366

Publication IDs

  • ORCID: /0000-0002-2604-0487/work/123748247
  • WOS: 000770507700001
  • Scopus: 85126521475

Abstract

It is challenging to verify that the planned security mechanisms are actually implemented in the software. In the context of model-based development, the implemented security mechanisms must capture all intended security properties that were considered in the design models. Assuring this compliance manually is labor intensive and can be error-prone. This work introduces the first semi-automatic technique for secure data flow compliance checks between design models and code. We develop heuristic-based automated mappings between a design-level model (SecDFD, provided by humans) and a code-level
representation (Program Model, automatically extracted from the implementation) in order to guide users in discovering compliance violations, and hence, potential security flaws in the code. These mappings enable an automated, and projectspecific static analysis of the implementation with respect to the desired security properties of the design model. We developed two types of security compliance checks and evaluated the entire approach on open source Java projects.

Publication metrics

PlumX, opens in new tab

Captures
20
Citations
19