relation: https://eprints.uet.vnu.edu.vn/eprints/id/eprint/3637/ title: An Approach to Analyze Software Security Requirements in ABAC Mode creator: Luong, Thanh Nhan creator: Vo, Dinh Hieu creator: Truong, Ninh Thuan subject: Information Technology (IT) description: Security has been a crucial aspect of most applications especially, critical-safety softwares. In fact, losing or leaking of sensitive data can lead to huge losses for organizations so software developers must always find ways to ensure the security properties for their products. In practice, attribute-based access control (ABAC) has been an effective, flexible and popular method to mitigate the risks of unauthorized accesses to resources in large and complex systems. Therefore, we introduce an approach for checking ABAC rules from source code of an application software against to its requirement specification. Our work includes of a formal definition about ABAC policy, method to implement ABAC into application as well as analyze access rules from the source code, and a algorithm to check analyzed ABAC rules against to its specification. The proposed approach can help programmers to detect the inconsistency between specification and implementation. We also illustrate our approach with an example in a medical information management system. date: 2019-12-12 type: Conference or Workshop Item type: PeerReviewed identifier: Luong, Thanh Nhan and Vo, Dinh Hieu and Truong, Ninh Thuan (2019) An Approach to Analyze Software Security Requirements in ABAC Mode. In: The NAFOSTED Conference on Information and Computer Science (NICS). (In Press) relation: https://edas.info/listConferencesAuthor.php?c=26598