2021
DOI: 10.1016/j.sysarc.2021.102073
|View full text |Cite
|
Sign up to set email alerts
|

Specification, detection, and treatment of STRIDE threats for software components: Modeling, formal methods, and tool support

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
11
0

Year Published

2021
2021
2024
2024

Publication Types

Select...
5
3

Relationship

3
5

Authors

Journals

citations
Cited by 26 publications
(11 citation statements)
references
References 15 publications
0
11
0
Order By: Relevance
“…3) Component Layer: The Component layer meta-model defines concepts related to the engineering of components (logical/physical). In the present context, we reuse the Component-Port-Connector (CPC) model presented in [20], with message passing-based communication primitives. It provides a recognized way of visualizing the system's structural and behavioral aspects, constituting the "component view" of the model.…”
Section: A Three-layered System Meta-model 1) Mission Layermentioning
confidence: 99%
“…3) Component Layer: The Component layer meta-model defines concepts related to the engineering of components (logical/physical). In the present context, we reuse the Component-Port-Connector (CPC) model presented in [20], with message passing-based communication primitives. It provides a recognized way of visualizing the system's structural and behavioral aspects, constituting the "component view" of the model.…”
Section: A Three-layered System Meta-model 1) Mission Layermentioning
confidence: 99%
“…This conceptual model captures two different viewsmission specification and property specification, where the latter extends the former. Some of the representative elements constituting this model are semantically inherited from the state-of-the-art artifacts proposed for rigorously defining the missions [17]- [21] and properties [22]. The meta-models corresponding to the aforementioned views are discussed in the following sub-sections, where both are implemented as UML profiles to provide a standardized modeling environment.…”
Section: A Modeling System Missions and Safety-security Objectivesmentioning
confidence: 99%
“…In some recent efforts, formal logics, like FOL and temporal logic, are used for rigorous specification of safety and security properties [22], [34], [35]. Some of these works (e.g., [34]) are nonetheless less oriented to cover integrated specification of high-level safety and security properties.…”
Section: Related Work and Positioningmentioning
confidence: 99%
See 1 more Smart Citation
“…Rouland et al [14,28] continue their metamodel definition with the addition of a component action-based specification, and a component and connector property specification metamodel. They describe possible actions of components by using messages in the system and then verify the absence of threats, defined by Microsoft's STRIDE methodology, in the modelled system's communication scheme.…”
Section: Metamodel Originsmentioning
confidence: 99%