Logo des Repositoriums
 

Integrating Security-Enriched Data Flow Diagrams Into Architecture-Based Confidentiality Analysis

dc.contributor.authorNiehues, Nils
dc.contributor.authorArp, Benjamin
dc.contributor.authorHüller, Tom
dc.contributor.authorSchwickerath, Felix
dc.contributor.authorBoltz, Nicolas
dc.contributor.authorHahner, Sebastian
dc.contributor.editorHerrmann, Andrea
dc.date.accessioned2025-01-08T13:30:57Z
dc.date.available2025-01-08T13:30:57Z
dc.date.issued2024
dc.description.abstractThe increasing complexity of modern software systems presents developers with significant challenges regarding the confidentiality of sensitive data. To this end, data flow diagrams serve as an effective tool for identifying potential confidentiality violations. Previous work in this area collected a data set comprising security-enriched data flow diagrams. Previous work on the security of microservice applications has created an extensive dataset of security-enriched data flow diagrams derived from open-source projects. The data set also includes security rules for microservices architectures specified in natural language. This paper presents an automated pipeline that converts descriptions of data flow diagrams with security rules into models suitable for automated information security analysis. Our evaluation based on the existing data set shows that the transformed models are highly accurate, establishing a gold standard for data flow-based confidentiality analysis.en
dc.identifier.issn0720-8928
dc.identifier.urihttps://dl.gi.de/handle/20.500.12116/45523
dc.language.isoen
dc.pubPlaceBonn
dc.publisherGesellschaft für Informatik e.V.
dc.relation.ispartofSoftwaretechnik-Trends Band 44, Heft 4
dc.relation.ispartofseriesSoftwaretechnik-Trends
dc.subjectconfidentiality
dc.subjectdata flow diagram
dc.subjecttransformation
dc.subjectautomated pipeline
dc.titleIntegrating Security-Enriched Data Flow Diagrams Into Architecture-Based Confidentiality Analysisen
dc.typeText/Conference Paper
mci.conference.dateNovember 6-7, 2024
mci.conference.locationLinz, Austria
mci.conference.sessiontitle15th Symposium on Software Performance 2024
mci.reference.pages48-50

Dateien

Originalbündel
1 - 1 von 1
Lade...
Vorschaubild
Name:
SSP24_15_camera-ready_9164.pdf
Größe:
206.45 KB
Format:
Adobe Portable Document Format