Aspect-Oriented Security Hardening of UML Design Models

Djedjiga Mouheb, Mourad Debbabi, Makan Pourzandi, Lingyu Wang, Mariam Nouh, Raha Ziarati, Dima Alhadidi, Chamseddine Talhi, Vitor Lima

  • 出版商: Springer
  • 出版日期: 2015-04-22
  • 售價: $2,400
  • 貴賓價: 9.5$2,280
  • 語言: 英文
  • 頁數: 237
  • 裝訂: Hardcover
  • ISBN: 3319161059
  • ISBN-13: 9783319161051
  • 相關分類: UML資訊安全
  • 海外代購書籍(需單獨結帳)

商品描述

This book comprehensively presents a novel approach to the systematic security hardening of software design models expressed in the standard UML language. It combines model-driven engineering and the aspect-oriented paradigm to integrate security practices into the early phases of the software development process. To this end, a UML profile has been developed for the specification of security hardening aspects on UML diagrams. In addition, a weaving framework, with the underlying theoretical foundations, has been designed for the systematic injection of security aspects into UML models.

The work is organized as follows: chapter 1 presents an introduction to software security, model-driven engineering, UML and aspect-oriented technologies. Chapters 2 and 3 provide an overview of UML language and the main concepts of aspect-oriented modeling (AOM) respectively. Chapter 4 explores the area of model-driven architecture with a focus on model transformations. The main approaches that are adopted in the literature for security specification and hardening are presented in chapter 5. After these more general presentations, chapter 6 introduces the AOM profile for security aspects specification. Afterwards, chapter 7 details the design and the implementation of the security weaving framework, including several real-life case studies to illustrate its applicability. Chapter 8 elaborates an operational semantics for the matching/weaving processes in activity diagrams, while chapters 9 and 10 present a denotational semantics for aspect matching and weaving in executable models following a continuation-passing style. Finally, a summary and evaluation of the work presented are provided in chapter 11.

The book will benefit researchers in academia and industry as well as students interested in learning about recent research advances in the field of software security engineering.

商品描述(中文翻譯)

本書全面介紹了一種新的方法,用於對以標準UML語言表示的軟體設計模型進行系統性安全加固。它結合了模型驅動工程和面向方面的範式,將安全實踐整合到軟體開發過程的早期階段。為此,已開發了一個UML配置文件,用於在UML圖中指定安全加固方面。此外,還設計了一個編織框架,並具有相應的理論基礎,用於將安全方面注入UML模型中。

本書的組織如下:第1章介紹了軟體安全、模型驅動工程、UML和面向方面的技術。第2章和第3章分別概述了UML語言和面向方面建模(AOM)的主要概念。第4章探討了以模型驅動架構為重點的模型轉換領域。第5章介紹了文獻中採用的主要方法,用於安全規範和加固。在這些更一般的介紹之後,第6章介紹了用於安全方面規範的AOM配置文件。隨後,第7章詳細介紹了安全編織框架的設計和實現,包括幾個實際案例研究,以說明其應用性。第8章詳述了活動圖中匹配/編織過程的操作語義,而第9章和第10章則以繼續傳遞風格的可執行模型為例,提出了關於方面匹配和編織的指示語義。最後,第11章提供了對所提出的工作的總結和評估。

本書將使學術界和工業界的研究人員以及對軟體安全工程領域的最新研究進展感興趣的學生受益。