Secure Data-Flow Compliance Checks between Models and Code Based on Automated Mappings (Summary)
- ,
- Katja Tuma,
- Daniel Strüber,
- Jan Jürjens,
- Riccardo Scandariato
- University of Koblenz,
- University of Gothenburg,
- Fraunhofer Institute for Software and Systems Engineering
Research Output:
Conference Article in Proceeding or Book/Report chapter
Article in proceedings
Open access
Publication Information
Output type
Research Output:
Conference Article in Proceeding or Book/Report chapter
Article in proceedings
Original language
EnglishPublication milestones
- Published - 2020
Publication status
Published - 2020
Place of publication
Bonn, GermanyPublisher
Gesellschaft für Informatik, GermanyISBN (Print)
9783885796947, 3885796945Publication IDs
- ORCID: /0000-0002-2604-0487/work/154220618
- Scopus: 85138740922
Host publication title
Software engineering 2020Abstract
We present our paper published at the 2019 edition of the International Conference on Model Driven Engineering Languages and Systems (MODELS) [Pe19]. During the development of security-critical software, the system implementation must capture the security properties postulated by
the architectural design. To iteratively guide the developer in discovering such compliance violations we introduce automated mappings. These mappings are created by searching for correspondences between a design-level model (Security Data Flow Diagram) and an implementation-level model (Program Model). We limit the search space by considering name similarities between model elements and code elements as well as by the use of heuristic rules for matching data-Ćow structures. The automated mappings support the designer in an early discovery of implementation absence, convergence, and divergence with respect to the planned software design as well as the discovery of secure data-Ćow
compliance violations. We provide a publicly available implementation of the approach and its evaluation on Ąve open source Java projects.
the architectural design. To iteratively guide the developer in discovering such compliance violations we introduce automated mappings. These mappings are created by searching for correspondences between a design-level model (Security Data Flow Diagram) and an implementation-level model (Program Model). We limit the search space by considering name similarities between model elements and code elements as well as by the use of heuristic rules for matching data-Ćow structures. The automated mappings support the designer in an early discovery of implementation absence, convergence, and divergence with respect to the planned software design as well as the discovery of secure data-Ćow
compliance violations. We provide a publicly available implementation of the approach and its evaluation on Ąve open source Java projects.
Publication metrics
PlumX, opens in new tab
Captures
9
Access to documents
Related Event
Title
International Conference on Software Engineering
Event type
ConferenceDate
06/07/2020 - 11/07/2020Location
VIRTUAL
