【24h】

Security-Driven Model-Based Dynamic Adaptation

机译:基于安全性模型的动态适应

获取原文
获取原文并翻译 | 示例

摘要

Security is a key-challenge for software engineering, especially when considering access control and software evolutions. No satisfying solution exists for maintaining the alignment of access control policies with the business logic. Current implementations of access control rely on the separation between the policy and the application code. In practice, this separation is not so strict and some rules are hard-coded within the application, making the evolution of the policy difficult. We propose a new methodology for implementing security-driven applications. Prom a policy defined by a security expert, we generate an architectural model, reflecting the access control policy. We leverage the advances in the models@runtime domain to keep this model synchronized with the running system. When the policy is updated, the architectural model is updated, which in turn reconfigures the running system. As a proof of concept, we apply the approach to the development of a library management system.
机译:安全性是软件工程的关键挑战,特别是在考虑访问控制和软件演进时。没有令人满意的解决方案来维持访问控制策略与业务逻辑的一致性。当前访问控制的实现依赖于策略和应用程序代码之间的分隔。实际上,这种分离不是那么严格,并且在应用程序内对某些规则进行了硬编码,从而使策略的发展变得困难。我们提出了一种用于实施安全性驱动的应用程序的新方法。提示由安全专家定义的策略,我们生成一个体系结构模型,以反映访问控制策略。我们利用models @ runtime域中的先进技术来使该模型与正在运行的系统保持同步。更新策略时,将更新体系结构模型,从而重新配置正在运行的系统。作为概念证明,我们将这种方法应用于图书馆管理系统的开发。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号