Formal model-based argument patterns for security cases


연구 분야: Verification



학회: EuroPLoP '23: Proceedings of the 28th European Conference on Pattern Languages of Programs


초록

Assuring that security requirements have been met and detecting flaws in the early phases of the system development is less expensive than changes after system deployment. The deployment of industrial critical systems requires a security assurance case that represents a credible argument, supported by evidence, demonstrating that the system satisfies its security requirements and objectives. Building arguments and generating evidence to support the claims of an assurance case is of utmost importance and should be done using a rigorous mathematical basis, namely formal methods. This paper proposes an approach to constructing security assurance cases using formal methods. The proposed approach involves the following three steps: (1) decomposing security requirements and deriving security threats; (2) formalizing the system model and security threats; and (3) deriving the security argument patterns supported by the results of the formal verification of the security requirements. We present the derived argument patterns using the Goal Structure Notation pattern notation. We apply the patterns to build security cases of an autonomous drone case study system.


Author Profile
Marwa Zeroual

Université Paris-Saclay CEA List France and IRIT CNRS UT2 France

Andorra
Author Profile
Brahim Hamid

IRIT CNRS UT2 France

France
Author Profile
Morayo Adedjouma

Université Paris-Saclay CEA List France

France

📄 논문 정보

발행 연도 2024년
인용수 3
출판 국가 Andorra, France
사이트 ACM
좋아요 수 0

연관 논문 목록 (195건)