Arşiv ve Dokümantasyon Merkezi
Dijital Arşivi

Model driven security framework for software design and verification

Basit öğe kaydını göster

dc.contributor Ph.D. Program in Computer Engineering.
dc.contributor.advisor Çağlayan, M. Ufuk.
dc.contributor.author Deveci, Engin.
dc.date.accessioned 2023-03-16T10:13:45Z
dc.date.available 2023-03-16T10:13:45Z
dc.date.issued 2015.
dc.identifier.other CMPE 2015 D48 PhD
dc.identifier.uri http://digitalarchive.boun.edu.tr/handle/123456789/12604
dc.description.abstract Information system security is receiving increasing attention every day because a security problem can cause serious nancial loss or even loss of lives. Some of these security problems occur as a result of poor design practices, where important security functionality is not designed properly and is directly implemented later in the development cycle in an unmethodical way. Researchers have put a great deal of effort into de ning processes and tools to design and develop more secure information systems. However, veri cation of the designed and developed security functionality is of utmost importance. In some cases, designs and codes also need to be formally or semi-formally veri ed and certi ed by authorities. The Common Criteria is one of the widely used universal frameworks for evaluating the security functionality of information systems. In this thesis, we propose a new framework, Model Driven Security Framework (MDSF), for the analysis, design and evaluation of security properties of the information systems. Our aim is to support information system developers and evaluation authorities who implement the higher-level Common Criteria (Levels 6 and 7) security assurance process using formal methods based on Uni ed Modelling Language (UML), Object Constraint Language (OCL), Promela and Spin. With MDSF, we extend UML to support security analysis and design on the UML models of the information system. In addition to UML, we use OCL in MDSF for threat identi - cation, consistency checking among diagrams and security policy enforcement in the design model. We also propose a model transformation and model checking approach to formally verify whether the design model satis es the security requirements listed in the analysis model.
dc.format.extent 30 cm.
dc.publisher Thesis (Ph.D.) - Bogazici University. Institute for Graduate Studies in Science and Engineering, 2015.
dc.subject.lcsh Software engineering.
dc.subject.lcsh Information systems.
dc.title Model driven security framework for software design and verification
dc.format.pages xviii, 213 leaves ;


Bu öğenin dosyaları

Bu öğe aşağıdaki koleksiyon(lar)da görünmektedir.

Basit öğe kaydını göster

Dijital Arşivde Ara


Göz at

Hesabım