2017Proceedings/Proceedings of the ... International Conference on Software Engineering and Knowledge EngineeringOpen access

Security Requirements for Tolerating Security Failures

Michael Shin, Don Pathirage

Open full text 3 citations

Abstract

This paper describes security failure-tolerant requirements, which tolerate the failures of security services that protect applications from security attacks.A security service, such as authentication, confidentiality or integrity security service, can be always broken down as advanced attack skills are coined.There is no security service that is forever secure.This paper describes an approach to developing the security failure-tolerant use case that specifies the security requirements for tolerating the breaches of security services.A security failure-tolerant use case is modeled along with application use case and security use case, and specified with application use case description.Threats to applications are identified and modeled to develop security failure-tolerant requirements.Online shopping system is used for illustrating security failure-tolerant requirements.

Open-access reader

About this research paper

What this paper is about

This paper describes security failure-tolerant requirements, which tolerate the failures of security services that protect applications from security attacks.A security service, such as authentication, confidentiality or integrity security service, can be always broken down as advanced attack skills are coined.There is no security service that is forever secure.This paper describes an approach to developing the security failure-tolerant use case that specifies the security requirements for tolerating the breaches of security services.A security failure-tolerant use case is modeled along with application use case and security use case, and specified with application use case description.Threats to applications are identified and modeled to develop security failure-tolerant requirements.Online shopping system is used for illustrating security failure-tolerant requirements.

Why it matters

OpenAlex reports 3 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

This paper describes security failure-tolerant requirements, which tolerate the failures of security services that protect applications from security attacks.A security service, such as authentication, confidentiality or integrity security service, can be always broken down as advanced attack skills are coined.There is no security service that is forever secure.This paper describes an approach to developing the security failure-tolerant use case that specifies the security requirements for tolerating the breaches of security services.A security failure-tolerant use case is modeled along with application use case and security use case, and specified with application use case description.Threats to applications are identified and modeled to develop security failure-tolerant requirements.Online shopping system is used for illustrating security failure-tolerant requirements.

Key concepts: Security service, Security testing, Computer security, Security through obscurity, Security information and event management, Computer science, Computer security model, Cloud computing security

Related papers

Back to paper searchBrowse research topicsOriginal source
Security Requirements for Tolerating Security Failures — Research Paper | ScholarLens