Specifying security in a composite system

Kabasele-Tenday, JM
(1998) 1st International Workshop on Information Security (ISW 97) — Location: JAPAN ADV INST SCI & TECHNOL, ISHIKAWA (Japan) (17.September.1997)

Files

pdfdocument.pdf
  • Restricted Access
  • Adobe PDF
  • 635.14 KB

Details

Authors
  • Kabasele-Tenday, JM
    Author
Abstract
This paper proposes a formal definition of "security" in a composite system. By composite system, we mean a system which is composed of an automated and a human part. This split of systems in two parts characterizes the computer environment where human presence is unavoidable. Our results are a generalization of [6]. The scope of [6] was limited to three access modes, that is read, write, execute. In this paper, we extend this scope by addressing all possible operations. We also provide a syntactic way, based on the proposed security formal definition, of describing threats during the requirement analysis process. To handle the security problem when designing a system, it is important to integrate threats in the requirements document. Up to now, there were only "methods" to derive threats [arbitrary or threat trees method], not to express them unambiguously.
Affiliations

Citations

Kabasele-Tenday, J. (1998). Specifying security in a composite system. Lecture Notes in Computer Science, 1396, 246-255. https://doi.org/10.1007/BFb0030425 (Original work published 1998)