Location via proxy:   [ UP ]  
[Report a bug]   [Manage cookies]                
skip to main content
10.1145/2593929.2593938acmconferencesArticle/Chapter ViewAbstractPublication PagesicseConference Proceedingsconference-collections
Article

Requirements-driven mediation for collaborative security

Published: 02 June 2014 Publication History

Abstract

Security is concerned with the protection of assets from intentional harm. Secure systems provide capabilities that enable such protection to satisfy some security requirements. In a world increasingly populated with mobile and ubiquitous computing technology, the scope and boundary of security systems can be uncertain and can change. A single functional component, or even multiple components individually, are often insufficient to satisfy complex security requirements on their own.
Adaptive security aims to enable systems to vary their protection in the face of changes in their operational environment. Collaborative security, which we propose in this paper, aims to exploit the selection and deployment of multiple, potentially heterogeneous, software-intensive components to collaborate in order to meet security requirements in the face of changes in the environment, changes in assets under protection and their values, and the discovery of new threats and vulnerabilities.
However, the components that need to collaborate may not have been designed and implemented to interact with one another collaboratively. To address this, we propose a novel framework for collaborative security that combines adaptive security, collaborative adaptation and an explicit representation of the capabilities of the software components that may be needed in order to achieve collaborative security. We elaborate on each of these framework elements, focusing in particular on the challenges and opportunities afforded by (1) the ability to capture, represent, and reason about the capabilities of different software components and their operational context, and (2) the ability of components to be selected and mediated at runtime in order to satisfy the security requirements. We illustrate our vision through a collaborative robotic implementation, and suggest some areas for future work.

References

[1]
A. Bennaceur. Dynamic Synthesis of Mediators in Ubiquitous Environments. PhD thesis, Université Paris VI, 2013. http://hal.inria.fr/tel-00849402/en.
[2]
A. Bennaceur, C. Chilton, M. Isberner, and B. Jonsson. Automated mediator synthesis: Combining behavioural and ontological reasoning. In Proc. of SEFM, 2013.
[3]
A. Bennaceur, V. Issarny, D. Sykes, F. Howar, M. Isberner, B. Steffen, R. Johansson, and A. Moschitti. Machine learning for emergent middleware. In Proc. of the Joint workshop on Intel. Methods for Soft. System Eng., JIMSE, 2012.
[4]
P. Bresciani, A. Perini, P. Giorgini, F. Giunchiglia, and J. Mylopoulos. Tropos: An agent-oriented software development methodology. Autonomous Agents and Multi-Agent Systems, 8(3), 2004.
[5]
Y.-D. Bromberg, P. Grace, L. Réveillère, and G. S. Blair. Bridging the interoperability gap: Overcoming combined application and middleware heterogeneity. In Proc. of Middleware, 2011.
[6]
L. Cavallaro, P. Sawyer, D. Sykes, N. Bencomo, and V. Issarny. Satisfying requirements for pervasive service compositions. In Proc. of the 7th Workshop on [email protected], 2012.
[7]
A. Computing et al. An architectural blueprint for autonomic computing. IBM White Paper, 2006.
[8]
Ö. E. Demir, P. T. Devanbu, N. Medvidovic, and E. Wohlstadter. Discoa: architectural adaptations for security and qos. ACM SIGSOFT Software Engineering Notes, 30(4), 2005.
[9]
E. Fernandez-Buglioni. Security patterns in practice: designing secure architectures using software patterns. John Wiley & Sons, 2013.
[10]
C. Ghezzi, L. S. Pinto, P. Spoletini, and G. Tamburrelli. Managing non-functional uncertainty via model-driven adaptivity. In Proc. of ICSE, 2013.
[11]
C. B. Haley, R. C. Laney, J. D. Moffett, and B. Nuseibeh. Security requirements engineering: A framework for representation and analysis. IEEE Trans. Software Eng., 34(1), 2008.
[12]
P. Inverardi and M. Tivoli. Automatic synthesis of modular connectors via composition of protocol mediation patterns. In Proc. of ICSE, 2013.
[13]
V. Issarny and A. Bennaceur. Composing distributed systems: Overcoming the interoperability challenge. In HATS International School on Formal Models for Components and Objects. Springer Verlag, 2012.
[14]
M. Jackson and P. Zave. Deriving specifications from requirements: An example. In Proc. of ICSE, 1995.
[15]
A. Lazarevic, V. Kumar, and J. Srivastava. Intrusion detection: A survey. In Managing Cyber Threats. Springer, 2005.
[16]
D. Lorenzoli, L. Mariani, and M. Pezzè. Automatic generation of software behavioral models. In Proc. of ICSE, 2008.
[17]
D. Lorenzoli and G. Spanoudakis. Detection of security and dependability threats: A belief based reasoning approach. In Proc. of the 3rd International Conference on Emerging Security Information, Systems and Technologie, SECURWARE, 2009.
[18]
D. Martin, M. Burstein, D. McDermott, S. McIlraith, M. Paolucci, K. Sycara, D. McGuinness, E. Sirin, and N. Srinivasan. Bringing semantics to web services with OWL-S. In Proc. of WWW, 2007.
[19]
L. Pasquale, C. Menghi, M. Salehie, L. Cavallaro, I. Omoronyia, and B. Nuseibeh. SecuriTAS: a tool for engineering adaptive security. In Proc. of FSE, 2012.
[20]
M. Salehie, L. Pasquale, I. Omoronyia, R. Ali, and B. Nuseibeh. Requirements-driven adaptive security: Protecting variable assets at runtime. In Proc. of RE, 2012.
[21]
A. Tanenbaum and M. Van Steen. Distributed systems: principles and paradigms. Prentice Hall, 2006.
[22]
G. Wiederhold. Mediators in the architecture of future information systems. IEEE Computer, 1992.
[23]
Z. Yang, Z. Zhou, B. H. C. Cheng, and P. K. McKinley. Enabling collaborative adaptation across legacy components. In Proc. of the 3rd Workshop on Adaptive and Reflective Middleware, ARM, 2004.
[24]
E. Yuan, N. Esfahani, and S. Malek. A systematic survey of self-protecting software systems. ACM Trans. on Autonomous and Adaptive Syst., to appear.

Cited By

View all
  • (2023)Provenance-Based Trust-Aware Requirements Engineering Framework for Self-Adaptive SystemsSensors10.3390/s2310462223:10(4622)Online publication date: 10-May-2023
  • (2021)Self-adaptive and secure mechanism for IoT based multimedia services: a surveyMultimedia Tools and Applications10.1007/s11042-020-10493-581:19(26685-26720)Online publication date: 27-Jan-2021
  • (2019)Enabling change-driven workflows in continuous information security managementProceedings of the 34th ACM/SIGAPP Symposium on Applied Computing10.1145/3297280.3297468(1924-1933)Online publication date: 8-Apr-2019
  • Show More Cited By

Index Terms

  1. Requirements-driven mediation for collaborative security

    Recommendations

    Comments

    Information & Contributors

    Information

    Published In

    cover image ACM Conferences
    SEAMS 2014: Proceedings of the 9th International Symposium on Software Engineering for Adaptive and Self-Managing Systems
    June 2014
    174 pages
    ISBN:9781450328647
    DOI:10.1145/2593929
    Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

    Sponsors

    In-Cooperation

    • TCSE: IEEE Computer Society's Tech. Council on Software Engin.

    Publisher

    Association for Computing Machinery

    New York, NY, United States

    Publication History

    Published: 02 June 2014

    Permissions

    Request permissions for this article.

    Check for updates

    Author Tags

    1. Security requirements
    2. collaborative adaptation
    3. mediation

    Qualifiers

    • Article

    Conference

    ICSE '14
    Sponsor:

    Acceptance Rates

    Overall Acceptance Rate 17 of 31 submissions, 55%

    Upcoming Conference

    ICSE 2025

    Contributors

    Other Metrics

    Bibliometrics & Citations

    Bibliometrics

    Article Metrics

    • Downloads (Last 12 months)8
    • Downloads (Last 6 weeks)0
    Reflects downloads up to 03 Oct 2024

    Other Metrics

    Citations

    Cited By

    View all
    • (2023)Provenance-Based Trust-Aware Requirements Engineering Framework for Self-Adaptive SystemsSensors10.3390/s2310462223:10(4622)Online publication date: 10-May-2023
    • (2021)Self-adaptive and secure mechanism for IoT based multimedia services: a surveyMultimedia Tools and Applications10.1007/s11042-020-10493-581:19(26685-26720)Online publication date: 27-Jan-2021
    • (2019)Enabling change-driven workflows in continuous information security managementProceedings of the 34th ACM/SIGAPP Symposium on Applied Computing10.1145/3297280.3297468(1924-1933)Online publication date: 8-Apr-2019
    • (2019)Specifying a New Requirement Model for Secure Adaptive SystemsThe Computer Journal10.1093/comjnl/bxz12463:8(1148-1167)Online publication date: 26-Dec-2019
    • (2019)Security Vulnerabilities and Issues of Traditional Wireless Sensors Networks in IoTPrinciples of Internet of Things (IoT) Ecosystem: Insight Paradigm10.1007/978-3-030-33596-0_21(519-549)Online publication date: 14-Nov-2019
    • (2018)Employing Consumer Wearables to Detect Office Workers' Cognitive Load for Interruption ManagementProceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies10.1145/31917642:1(1-20)Online publication date: 26-Mar-2018
    • (2018)Visualizing Location Uncertainty on Mobile DevicesProceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies10.1145/31917622:1(1-22)Online publication date: 26-Mar-2018
    • (2018)CHARIOTACM Transactions on Cyber-Physical Systems10.1145/31348442:3(1-37)Online publication date: 13-Jun-2018
    • (2018)Feature-Driven Mediator SynthesisACM Transactions on Cyber-Physical Systems10.1145/31348432:3(1-25)Online publication date: 13-Jun-2018
    • (2018)Security Assessment of Robotic System with Inter-Machine Interaction2018 International Russian Automation Conference (RusAutoCon)10.1109/RUSAUTOCON.2018.8501753(1-7)Online publication date: Sep-2018
    • Show More Cited By

    View Options

    Get Access

    Login options

    View options

    PDF

    View or Download as a PDF file.

    PDF

    eReader

    View online with eReader.

    eReader

    Media

    Figures

    Other

    Tables

    Share

    Share

    Share this Publication link

    Share on social media