A Formal Security Requirements Model for a Grid-based Operating System
Author(s) -
Benjamin Aziz,
Álvaro Arenas,
Juan Bicarregui,
Brian Matthews,
Erica Yang
Publication year - 2007
Publication title -
electronic workshops in computing
Language(s) - English
Resource type - Conference proceedings
ISSN - 1477-9358
DOI - 10.14236/ewic/fmi2007.1
Subject(s) - computer science , goal modeling , grid , computer security model , authorization , requirements engineering , focus (optics) , requirements analysis , software engineering , computer security , operating system , software , physics , geometry , mathematics , optics
In this paper, we discuss the use of formal requirements engineering techniques in capturing security requirements for a Grid-based operating system. Our approach is based on the KAOS methodology in which system goals can be refined to sets of requirements that can be satisfied by agents performing specific operations on system objects. We focus on the example of one security goal of interest to Grid-based systems, namely the authorisation to access data, and show how this goal can be refined into system requirements. Then we develop a model of anti-goals, and show how the model captures vulnerabilities that undermine the main security goal.
Accelerating Research
Robert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom
Address
John Eccles HouseRobert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom