作者
Narges Khakpour, Charilaos Skandylas, Goran Saman Nariman, Danny Weyns
发表日期
2019/5/25
研讨会论文
2019 IEEE/ACM 14th International Symposium on Software Engineering for Adaptive and Self-Managing Systems (SEAMS)
页码范围
114-125
出版商
IEEE
简介
As any software system, a self-adaptive system is subject to security threats. However, applying self-adaptation may introduce additional threats. So far, little research has been devoted to this important problem. In this paper, we propose an approach for vulnerability analysis of architecture-based adaptations in self-adaptive systems using threat modeling and analysis techniques. To this end, we specify components' vulnerabilities and the system architecture formally and generate an attack model that describes the attacker's strategies to attack the system by exploiting different vulnerabilities. We use a set of security metrics to quantitatively assess the security risks of adaptations based on the produced attack model which enables the system to consider security aspects while choosing an adaptation to apply to the system. We automate and incorporate our approach into the Rainbow framework, allowing for secure …
引用总数
2020202120222023202445632
学术搜索中的文章
N Khakpour, C Skandylas, GS Nariman, D Weyns - 2019 IEEE/ACM 14th International Symposium on …, 2019