Aspect-Oriented Security Hardening of UML Design Models

  • Djedjiga Mouheb
  • Mourad Debbabi
  • Makan Pourzandi
  • Lingyu Wang
  • Mariam Nouh
  • Raha Ziarati
  • Dima Alhadidi
  • Chamseddine Talhi
  • Vitor Lima

Table of contents

  1. Front Matter
    Pages i-xviii
  2. Djedjiga Mouheb, Mourad Debbabi, Makan Pourzandi, Lingyu Wang, Mariam Nouh, Raha Ziarati et al.
    Pages 1-10
  3. Djedjiga Mouheb, Mourad Debbabi, Makan Pourzandi, Lingyu Wang, Mariam Nouh, Raha Ziarati et al.
    Pages 11-22
  4. Djedjiga Mouheb, Mourad Debbabi, Makan Pourzandi, Lingyu Wang, Mariam Nouh, Raha Ziarati et al.
    Pages 23-33
  5. Djedjiga Mouheb, Mourad Debbabi, Makan Pourzandi, Lingyu Wang, Mariam Nouh, Raha Ziarati et al.
    Pages 35-45
  6. Djedjiga Mouheb, Mourad Debbabi, Makan Pourzandi, Lingyu Wang, Mariam Nouh, Raha Ziarati et al.
    Pages 47-67
  7. Djedjiga Mouheb, Mourad Debbabi, Makan Pourzandi, Lingyu Wang, Mariam Nouh, Raha Ziarati et al.
    Pages 69-84
  8. Djedjiga Mouheb, Mourad Debbabi, Makan Pourzandi, Lingyu Wang, Mariam Nouh, Raha Ziarati et al.
    Pages 85-136
  9. Djedjiga Mouheb, Mourad Debbabi, Makan Pourzandi, Lingyu Wang, Mariam Nouh, Raha Ziarati et al.
    Pages 137-162
  10. Djedjiga Mouheb, Mourad Debbabi, Makan Pourzandi, Lingyu Wang, Mariam Nouh, Raha Ziarati et al.
    Pages 163-192
  11. Djedjiga Mouheb, Mourad Debbabi, Makan Pourzandi, Lingyu Wang, Mariam Nouh, Raha Ziarati et al.
    Pages 193-213
  12. Djedjiga Mouheb, Mourad Debbabi, Makan Pourzandi, Lingyu Wang, Mariam Nouh, Raha Ziarati et al.
    Pages 215-219
  13. Back Matter
    Pages 221-237

About this book

Introduction

This book comprehensively presents a novel approach to the systematic security hardening of software design models expressed in the standard UML language. It combines model-driven engineering and the aspect-oriented paradigm to integrate security practices into the early phases of the software development process. To this end, a UML profile has been developed for the specification of security hardening aspects on UML diagrams. In addition, a weaving framework, with the underlying theoretical foundations, has been designed for the systematic injection of security aspects into UML models.

The work is organized as follows: chapter 1 presents an introduction to software security, model-driven engineering, UML and aspect-oriented technologies. Chapters 2 and 3 provide an overview of UML language and the main concepts of aspect-oriented modeling (AOM) respectively. Chapter 4 explores the area of model-driven architecture with a focus on model transformations. The main approaches that are adopted in the literature for security specification and hardening are presented in chapter 5. After these more general presentations, chapter 6 introduces the AOM profile for security aspects specification. Afterwards, chapter 7 details the design and the implementation of the security weaving framework, including several real-life case studies to illustrate its applicability. Chapter 8 elaborates an operational semantics for the matching/weaving processes in activity diagrams, while chapters 9 and 10 present a denotational semantics for aspect matching and weaving in executable models following a continuation-passing style. Finally, a summary and evaluation of the work presented are provided in chapter 11.

The book will benefit researchers in academia and industry as well as students interested in learning about recent research advances in the field of software security engineering.

Keywords

OCL UML aspect weaving aspect-oriented modeling model-based security model-driven software engineering software security engineering systems security

Authors and affiliations

  • Djedjiga Mouheb
    • 1
  • Mourad Debbabi
    • 2
  • Makan Pourzandi
    • 3
  • Lingyu Wang
    • 4
  • Mariam Nouh
    • 5
  • Raha Ziarati
    • 6
  • Dima Alhadidi
    • 7
  • Chamseddine Talhi
    • 8
  • Vitor Lima
    • 9
  1. 1.Concordia UniversityMontrealCanada
  2. 2.Concordia UniversityMontrealCanada
  3. 3.Ericsson Canada Inc.Ville Mount-RoyalCanada
  4. 4.Concordia UniversityMontrealCanada
  5. 5.McGill UniversityMontrealCanada
  6. 6.Sophos Inc.VancouverCanada
  7. 7.Zayed UniversityDubaiUtd.Arab.Emir.
  8. 8.École de Technologie SupérieureMontréalCanada
  9. 9.MontrealCanada

Bibliographic information

  • DOI https://doi.org/10.1007/978-3-319-16106-8
  • Copyright Information Springer International Publishing Switzerland 2015
  • Publisher Name Springer, Cham
  • eBook Packages Computer Science
  • Print ISBN 978-3-319-16105-1
  • Online ISBN 978-3-319-16106-8
  • About this book
Industry Sectors
Pharma
Automotive
Chemical Manufacturing
Biotechnology
Electronics
Telecommunications
Energy, Utilities & Environment
Aerospace