VNU-UET Repository

An Approach to Analyze Software Security Requirements in ABAC Mode

Luong, Thanh Nhan and Vo, Dinh Hieu and Truong, Ninh Thuan (2019) An Approach to Analyze Software Security Requirements in ABAC Mode. In: The NAFOSTED Conference on Information and Computer Science (NICS). (In Press)

Full text not available from this repository.

Abstract

Security has been a crucial aspect of most applications especially, critical-safety softwares. In fact, losing or leaking of sensitive data can lead to huge losses for organizations so software developers must always find ways to ensure the security properties for their products. In practice, attribute-based access control (ABAC) has been an effective, flexible and popular method to mitigate the risks of unauthorized accesses to resources in large and complex systems. Therefore, we introduce an approach for checking ABAC rules from source code of an application software against to its requirement specification. Our work includes of a formal definition about ABAC policy, method to implement ABAC into application as well as analyze access rules from the source code, and a algorithm to check analyzed ABAC rules against to its specification. The proposed approach can help programmers to detect the inconsistency between specification and implementation. We also illustrate our approach with an example in a medical information management system.

Item Type: Conference or Workshop Item (Paper)
Subjects: Information Technology (IT)
Divisions: School of Aerospace Engineering (SAE)
Depositing User: Prof. Ninh Thuan Truong
Date Deposited: 28 Nov 2019 01:46
Last Modified: 28 Nov 2019 01:46
URI: http://eprints.uet.vnu.edu.vn/eprints/id/eprint/3637

Actions (login required)

View Item View Item