A Pattern-based Security Solution for Software Systems with Architectural Weaknesses | IEEE Conference Publication | IEEE Xplore

A Pattern-based Security Solution for Software Systems with Architectural Weaknesses


Abstract:

Security patterns are solutions to recurring security issues that can be applied to mitigate vulnerabilities in a software system. Application developers may be unaware o...Show More

Abstract:

Security patterns are solutions to recurring security issues that can be applied to mitigate vulnerabilities in a software system. Application developers may be unaware of the vulnerabilities of their own system, leaving it vulnerable to attacks. To improve security, the system needs security implementation in its architecture instead of implementing at local levels. This, in turn, requires an effort in building security into the design. Applying security patterns would be one way to accomplish this task. Security patterns define ways to express security requirements and solutions concisely, as well as providing vocabulary for designers seeking security controls in their systems. Little research has been done in the area of matching a security pattern with a particular vulnerability existing in a software system. In this research, authors have primarily focused on filling this gap to map a security pattern that could be a potential solution to a major security vulnerability found in the system. The authors’ previous research proposed a methodology to identify the missing security pattern to provide an architectural security solution. In this research, authors conducted a case-study on a software application that has little architectural design for security. The research results show that architectural security solutions are applicable even for a software system that lack an architectural design.
Date of Conference: 10-12 November 2021
Date Added to IEEE Xplore: 15 January 2025
ISBN Information:
Conference Location: Altoona, PA, USA
References is not available for this document.

References is not available for this document.
Contact IEEE to Subscribe

References

References is not available for this document.