Expediting the design and development of secure cloud-based mobile apps


연구 분야: Infrastructure



학회: International Journal of Information Security


초록

The adoption and popularity of mobile devices by end-users is partially driven by the increasing development and availability of mobile applications that can aid solving different problems and provide access to services in a wide range of domains or categories, namely healthcare, education, e-commerce or entertainment. While these applications use and benefit from the combination of a wide panoply of technologies from the Internet of Things, fog and cloud computing, data security and privacy are typically not fully taken into account before the creation of many mobile applications or during the software development phases. This paper presents an in-depth approach to modeling attacks on the specific cloud and mobile ecosystem, given its importance in the process of secure application development. Moreover, aiming at bridging the knowledge gap between developers and security experts, this paper presents an alpha version of the security by design for cloud and mobile ecosystem (SECD4CLOUDMOBILE) framework. SECD4CLOUDMOBILE is a set of tools that covers cloud and mobile security requirement elicitation (CMSRE), cloud and mobile security best practices guidelines (CMSBPG), cloud mobile attack modeling elicitation (CMAME), and cloud mobile security test specification and tools (CM2ST). The purpose of the framework is to provide cloud and mobile application developers useful readily applicable information and guidelines, striving to bring security engineering and software engineering closer, in a more accessible and automated manner, aiming at the incorporation of security by construction. Finally, the paper presents some preliminary results and discussion.


Author Profile
Francisco T. Chimuco

Universidade da Beira Interior and Instituto de Telecomunicações Rua Marquês D’Ávila e Bolama Castelo Branco 6201-001 Covilhã Portugal

Andorra
Author Profile
Joāo B. F. Sequeiros

Instituto Superior de Ciências de Educação da Huíla Rua Sarmento Rodrigues 230 Lubango Huíla Angola

Angola
Author Profile
Tiago M. C. Simōes

Universidade da Beira Interior and Instituto de Telecomunicações Rua Marquês D’Ávila e Bolama Castelo Branco 6201-001 Covilhã Portugal

Andorra

📄 논문 정보

발행 연도 2024년
인용수 0
출판 국가 Angola, Andorra
사이트 Springer
좋아요 수 0

연관 논문 목록 (244건)