2016Unpublished venueRequires access

Embedding Model-Based Security Policies in Software Development

Javier Navarro-Machuca, Li‐Chiou Chen

Open publisher page 2 citations

Abstract

Security in software applications is frequently an afterthought. Even if developers are aware of security policies and software vulnerabilities, they possess little knowledge of how to implement security polices while developing applications. In addition, the lack of support for tools and security automation makes it more challenging to incorporate security policies. In this paper we have proposed a security policy enforcement mechanism to incorporate security policies for data fields in transactions of software application during its development phase. The objective is to facilitate developers implementing security policies easily. The extensibility of our approach gives the flexibility to accommodate different security policy schemas and to implement various security policies on sensitive data. With the simplicity of mapping data fields of business structures with security policy definitions, our approach provides the programmers, business domain experts and security experts a collaborative process to define and incorporate security policies in software.

About this research paper

What this paper is about

Security in software applications is frequently an afterthought. Even if developers are aware of security policies and software vulnerabilities, they possess little knowledge of how to implement security polices while developing applications. In addition, the lack of support for tools and security automation makes it more challenging to incorporate security policies. In this paper we have proposed a security policy enforcement mechanism to incorporate security policies for data fields in transactions of software application during its development phase. The objective is to facilitate developers implementing security policies easily. The extensibility of our approach gives the flexibility to accommodate different security policy schemas and to implement various security policies on sensitive data. With the simplicity of mapping data fields of business structures with security policy definitions, our approach provides the programmers, business domain experts and security experts a collaborative process to define and incorporate security policies in software.

Why it matters

OpenAlex reports 2 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Security in software applications is frequently an afterthought. Even if developers are aware of security policies and software vulnerabilities, they possess little knowledge of how to implement security polices while developing applications. In addition, the lack of support for tools and security automation makes it more challenging to incorporate security policies. In this paper we have proposed a security policy enforcement mechanism to incorporate security policies for data fields in transactions of software application during its development phase. The objective is to facilitate developers implementing security policies easily. The extensibility of our approach gives the flexibility to accommodate different security policy schemas and to implement various security policies on sensitive data. With the simplicity of mapping data fields of business structures with security policy definitions, our approach provides the programmers, business domain experts and security experts a collaborative process to define and incorporate security policies in software.

Key concepts: Computer science, Software security assurance, Computer security model, Security testing, Computer security, Security through obscurity, Security policy, Security engineering

Related papers

Back to paper searchBrowse research topicsOriginal source
Embedding Model-Based Security Policies in Software Development — Research Paper | ScholarLens