File(s) under permanent embargo
Automated software architecture security risk analysis using formalized signatures
conference contribution
posted on 2013-10-30, 00:00 authored by M Almorsy, John Grundy, Amani IbrahimReviewing software system architecture to pinpoint potential security flaws before proceeding with system development is a critical milestone in secure software development lifecycles. This includes identifying possible attacks or threat scenarios that target the system and may result in breaching of system security. Additionally we may also assess the strength of the system and its security architecture using well-known security metrics such as system attack surface, Compartmentalization, least-privilege, etc. However, existing efforts are limited to specific, predefined security properties or scenarios that are checked either manually or using limited toolsets. We introduce a new approach to support architecture security analysis using security scenarios and metrics. Our approach is based on formalizing attack scenarios and security metrics signature specification using the Object Constraint Language (OCL). Using formal signatures we analyse a target system to locate signature matches (for attack scenarios), or to take measurements (for security metrics). New scenarios and metrics can be incorporated and calculated provided that a formal signature can be specified. Our approach supports defining security metrics and scenarios at architecture, design, and code levels. We have developed a prototype software system architecture security analysis tool. To the best of our knowledge this is the first extensible architecture security risk analysis tool that supports both metric-based and scenario-based architecture security analysis. We have validated our approach by using it to capture and evaluate signatures from the NIST security principals and attack scenarios defined in the CAPEC database.
History
Event
Software Engineering. International Conference (35th : 2013 : San Francisco, California)Pagination
662 - 671Publisher
IEEELocation
San Francisco, Calif.Place of publication
Piscataway, N.J.Publisher DOI
Start date
2013-05-18End date
2013-05-26ISSN
0270-5257ISBN-13
9781467330763Language
engPublication classification
E Conference publication; E1.1 Full written paper - refereedCopyright notice
2013, IEEETitle of proceedings
ICSE 2013 : Proceedings of the 35th International Conference on Software EngineeringUsage metrics
Categories
No categories selectedKeywords
software securityArchitecture Security Risk analysisformal attack patterns specificationcommon attack patterns enumeration and classification (CAPEC)Science & TechnologyTechnologyComputer Science, Software EngineeringComputer Science, Theory & MethodsEngineering, Electrical & ElectronicComputer ScienceEngineering