首页> 外文学位 >Pluggable Model-Based Security Policy Enforcement Mechanism for Software Development.
【24h】

Pluggable Model-Based Security Policy Enforcement Mechanism for Software Development.

机译:用于软件开发的基于可插拔模型的安全策略实施机制。

获取原文
获取原文并翻译 | 示例

摘要

Security in software applications is frequently an afterthought. Even if developers are aware of software vulnerabilities, they possess little knowledge of how to secure the applications while writing codes. In addition, the lack of tools for security automation makes it more challenging to protect systems and applications. This dissertation introduces a framework to incorporate security policies for data fields in the transactions of software application during its development phase. The objective is to facilitate developers to apply security policies on the data required by the regulations. The extensibility of the presented model gives the flexibility to accommodate different security requirements and to implement them as security functions. With the simplicity of mapping data fields of business structures with security policies and their associated security functions, this approach provides the programmers, business domain experts and security experts a collaborative process to define and incorporate security requirements in software. The proposed model-based security policy mechanism addresses the complexity of securing confidential information at the process level by enforcing pre-defined security policies on the data before the data is transmitted outside the application boundary, regardless of the destination or repository that the data will be stored. The separation of security policies and the application provides a granular control to protect the data field via different security techniques such as access control or encryption. This mechanism is flexible so that it can be used in either legacy applications or new applications. The application of this approach on the payment card industry payment application data security standard has been evaluated to validate the flexibility and extensibility of the proposed model.
机译:软件应用程序中的安全性通常是事后的想法。即使开发人员意识到软件漏洞,他们对编写代码时如何保护应用程序也不了解。此外,缺少用于安全自动化的工具,使得保护系统和应用程序更具挑战性。本文介绍了一个框架,该框架将数据字段的安全策略纳入软件应用程序开发阶段的事务中。目的是促进开发人员将安全策略应用于法规要求的数据。所提供模型的可扩展性提供了适应不同安全要求并将其实现为安全功能的灵活性。通过将业务结构的数据字段与安全策略及其相关的安全功能进行映射的简单性,此方法为程序员,业务领域专家和安全专家提供了一个协作过程,以定义并将安全要求纳入软件中。所提出的基于模型的安全策略机制通过在数据传输到应用程序边界之外之前对数据强制执行预定义的安全策略,从而解决了在流程级别保护机密信息的复杂性,而与数据将到达的目的地或存储库无关。存储。安全策略和应用程序的分离提供了粒度控制,以通过不同的安全技术(例如访问控制或加密)来保护数据字段。此机制很灵活,因此可以在旧应用程序或新应用程序中使用。已对该方法在支付卡行业支付应用程序数据安全标准中的应用进行了评估,以验证所提出模型的灵活性和可扩展性。

著录项

  • 作者

    Navarro-Machuca, Javier.;

  • 作者单位

    Pace University.;

  • 授予单位 Pace University.;
  • 学科 Computer science.;Information technology.
  • 学位 D.P.S.
  • 年度 2016
  • 页码 199 p.
  • 总页数 199
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号