The Experts below are selected from a list of 76284 Experts worldwide ranked by ideXlab platform

Myeonggil Choi - One of the best experts on this subject based on the ideXlab platform.

  • ISPEC - An empirical study of quality and cost based Security engineering
    Information Security Practice and Experience, 2006
    Co-Authors: Tai-myung Chung, Myeonggil Choi
    Abstract:

    For reliability and confidentiality of information Security systems, the Security engineering methodologies are accepted in many organizations. A Security institution in Korea faced the effectiveness of Security engineering. To solve the problems of Security engineering, the institution creates a Security Methodology called ISEM, and a tool called SENT. This paper presents ISEM Methodology considering both product assurance and production processes take advantages in terms of quality and cost. ISEM Methodology can make up for the current Security engineering Methodology. For support ISEM Methodology, SENT tool, which is operated in Internet, support the production processes and the product assurances which ISEM demands automatically.

  • An Empirical Study of Quality and Cost Based Security Engineering
    Information Security Practice and Experience, 2006
    Co-Authors: Seok Lee, Tai-myung Chung, Myeonggil Choi
    Abstract:

    For reliability and confidentiality of information Security systems, the Security engineering methodologies are accepted in\n many organizations. A Security institution in Korea faced the effectiveness of Security engineering. To solve the problems\n of Security engineering, the institution creates a Security Methodology called ISEM, and a tool called SENT. This paper presents\n ISEM Methodology considering both product assurance and production processes take advantages in terms of quality and cost.\n ISEM Methodology can make up for the current Security engineering Methodology. For support ISEM Methodology, SENT tool, which\n is operated in Internet, support the production processes and the product assurances which ISEM demands automatically.

Eduardo B. Fernandez - One of the best experts on this subject based on the ideXlab platform.

  • ASE: A comprehensive pattern-driven Security Methodology for distributed systems
    Computer Standards & Interfaces, 2015
    Co-Authors: Anton V. Uzunov, Eduardo B. Fernandez, Katrina Falkner
    Abstract:

    Abstract Incorporating Security features is one of the most important and challenging tasks in designing distributed systems. Over the last decade, researchers and practitioners have come to recognize that the incorporation of Security features should proceed by means of a structured, systematic approach, combining principles from both software and Security engineering. Such systematic approaches, particularly those implying some sort of process aligned with the development life-cycle, are termed Security methodologies . There are a number of Security methodologies in the literature, of which the most flexible and, according to a recent survey, most satisfactory from an industry-adoption viewpoint are methodologies that encapsulate their Security solutions in some fashion, especially via the use of Security patterns . While the literature does present several mature pattern-driven Security methodologies with either a general or a highly specific system applicability, there are currently no (pattern-driven) Security methodologies specifically designed for general distributed systems. Going further, there are also currently no methodologies with mixed specific applicability, e.g. for both general and peer-to-peer distributed systems. In this paper we aim to fill these gaps by presenting a comprehensive pattern-driven Security Methodology – arrived at by applying a previously devised approach to engineering Security methodologies – specifically designed for general distributed systems, which is also capable of taking into account the specifics of peer-to-peer systems as needed. Our Methodology takes the principle of encapsulation several steps further, by employing patterns not only for the incorporation of Security features (via Security solution frames), but also for the modeling of threats, and even as part of its process. We illustrate and evaluate the presented Methodology in detail via a realistic example – the development of a distributed system for file sharing and collaborative editing. In both the presentation of the Methodology and example our focus is on the early life-cycle phases (analysis and design).

  • A comprehensive pattern-oriented approach to engineering Security methodologies
    Information and Software Technology, 2015
    Co-Authors: Anton V. Uzunov, Katrina Falkner, Eduardo B. Fernandez
    Abstract:

    Abstract Context Developing secure software systems is an issue of ever-growing importance. Researchers have generally come to acknowledge that to develop such systems successfully, their Security features must be incorporated in the context of a systematic approach: a Security Methodology. There are a number of such methodologies in the literature, but no single Security Methodology is adequate for every situation, requiring the construction of “fit-to-purpose” methodologies or the tailoring of existing methodologies to the project specifics at hand. While a large body of research exists addressing the same requirement for development methodologies – constituting the field of Method Engineering – there is nothing comparable for Security methodologies as such; in fact, the topic has never been studied before in such a context. Objective In this paper we draw inspiration from a number of Method Engineering ideas and fill the latter gap by proposing a comprehensive approach to engineering Security methodologies. Method Our approach is embodied in three interconnected parts: a framework of interrelated Security process patterns; a Security-specific meta-model; and a meta-Methodology to guide engineers in using the latter artefacts in a step-wise fashion. A UML-inspired notation is used for representing all pattern-based Methodology models during design and construction. The approach is illustrated and evaluated by tailoring an existing, real-life Security Methodology to a distributed-system-specific project situation. Results The paper proposes a novel pattern-oriented approach to modeling, constructing, tailoring and combining Security methodologies, which is the very first and currently sole such approach in the literature. We illustrate and evaluate our approach in an academic setting, and perform a feature analysis to highlight benefits and deficiencies. Conclusion Using our proposal, developers, architects and researchers can analyze and engineer Security methodologies in a structured, systematic fashion, taking into account all Security Methodology aspects.

  • Australian Software Engineering Conference - A Comprehensive Pattern-Driven Security Methodology for Distributed Systems
    2014 23rd Australian Software Engineering Conference, 2014
    Co-Authors: Anton V. Uzunov, Eduardo B. Fernandez, Katrina Falkner
    Abstract:

    Incorporating Security features is one of the most important and challenging tasks in designing distributed systems. Over the last decade, researchers and practitioners have come to recognize that the incorporation of Security features should proceed by means of a systematic approach, combining principles from both software and Security engineering. Such systematic approaches, particularly those implying some sort of process aligned with the development life-cycle, are termed Security methodologies. One of the most important classes of such methodologies is based on the use of Security patterns. While the literature presents a number of pattern-driven Security methodologies, none of them are designed specifically for general distributed systems. Going further, there are also currently no methodologies with mixed specific applicability, e.g. for both general and peer-to-peer distributed systems. In this paper we aim to fill these gaps by presenting a comprehensive pattern-driven Security Methodology specifically designed for general distributed systems, which is also capable of taking into account the specifics of peer-to-peer systems. Our Methodology takes the principle of encapsulation several steps further, by employing patterns not only for the incorporation of Security features (via Security solution frames), but also for the modeling of threats, and even as part of its process. We illustrate and evaluate the presented Methodology via a realistic example -- the development of a distributed system for file sharing and collaborative editing. In both the presentation of the Methodology and example our focus is on the early life-cycle phases (analysis and design).

Matthew Warren - One of the best experts on this subject based on the ideXlab platform.

  • Evaluating the effectiveness of an e-business Security Methodology using a case study approach
    2007
    Co-Authors: Damien Hutchinson, Matthew Warren
    Abstract:

    The findings of three case studies resulting from the application of the Australian Small to Medium Enterprise E-business Security Methodology (ASME-EBSM) to each of the SME sectors comprising micro, small and medium businesses are examined. First a comparison of the findings relating to the SME sectors is discussed. The similarities and differences including the challenges experienced by the three sectors concerning the application of e-business Security management within their respective e-business operational environments are presented. Second the process of applying the ASME-EBSM is reviewed with reflections upon the development and constituents of the Methodology. The paper describes how a number of case studies were undertaken to validate the ASME-EBSM approach.

  • E-business Security management for Australian small SMEs - a case study
    2006
    Co-Authors: Damien Hutchinson, Matthew Warren
    Abstract:

    Small and Medium sized Enterprises (SMEs) play an important role within the Australian economy. There is a strong business case for Australian SMEs to be involved in e-business, which has been realised as the use of the Internet for performing business activities continues to increase. The evidence available indicates the uptake and advancement of performing e-business activities shall be dependent on the ability of Australian SMEs to secure their e-business systems. This paper presents the results of a case study, which applied a previously developed Methodology to a small SME e-business system. The purpose was to validate the ability of the Australian Small to Medium Enterprise E-business Security Methodology (ASME-EBSM) to provide an effective Security management strategy for Australian SMEs. The outcome demonstrated that this approach was both feasible and realistic for providing recommendations to secure the e-business activities performed and to protect the small SME e-business system.

  • A risk analysis approach to critical information infrastructure protection
    2004
    Co-Authors: T. B. Busuttil, Matthew Warren
    Abstract:

    Critical Information Infrastructure (CII) has become a priority for all levels of management, It is one of the key components of efficient business and business continuity plans. There is a need for a new Security Methodology to deal with the new and unique attack threats and vulnerabilities associated with the new information technology Security paradigm. Critical Information Infrastructure Protection - Risk Analysis Methodology (ClIP-RAM), is a new Security risk analysis method which copes with the shift from computer/information Security to critical information infrastructure protection. This type of Methodology is the next step toward handling information technology Security risk at all levels from upper management information Security down to firewall configurations. The paper will present the Methodology of the new techniques and their application to critical information infrastructure protection. The associated advantages of this Methodology will also be discussed.

  • CIIP-RAM - a step-wise Security risk analysis Methodology for critical information infrastructure protection
    2003
    Co-Authors: T. B. Busuttil, Matthew Warren
    Abstract:

    Wilh the protection of critical information infrastructure becoming a priority for all levels of management. there is a need for a new Security Methodology to deal with the new and unique attack threats and vulnerabilities associated with the new information technology Security paradigm. The fourth generation Security risk analysis melhod which copes wilh the shift from computer/information Security to critical information iinfrastructure protectionl is lhe next step toward handling Security risk at all levels. The paper will present the Methodology of fourth generation models and their application to critical information infrastructure protection and the associated advantagess of this Methodology.

  • A conceptual approach to information warfare : Security risk analysis
    2002
    Co-Authors: T. B. Busuttil, Matthew Warren
    Abstract:

    With information warfare (IW) becoming a reality, the need for a new Security Methodology to deal with the new and unique attack threats and vulnerabilities associated with the new information technology Security paradigm. With the shift from computer Security to information warfare, logical transformation models (LTMS) were looked at as a solution to quantifying information system requirements. The paper will introduce the concepts involved with fourth generational models and it's application to IW. The basic advantages and disadvantages will also be discussed and presented.

Anton V. Uzunov - One of the best experts on this subject based on the ideXlab platform.

  • ASE: A comprehensive pattern-driven Security Methodology for distributed systems
    Computer Standards & Interfaces, 2015
    Co-Authors: Anton V. Uzunov, Eduardo B. Fernandez, Katrina Falkner
    Abstract:

    Abstract Incorporating Security features is one of the most important and challenging tasks in designing distributed systems. Over the last decade, researchers and practitioners have come to recognize that the incorporation of Security features should proceed by means of a structured, systematic approach, combining principles from both software and Security engineering. Such systematic approaches, particularly those implying some sort of process aligned with the development life-cycle, are termed Security methodologies . There are a number of Security methodologies in the literature, of which the most flexible and, according to a recent survey, most satisfactory from an industry-adoption viewpoint are methodologies that encapsulate their Security solutions in some fashion, especially via the use of Security patterns . While the literature does present several mature pattern-driven Security methodologies with either a general or a highly specific system applicability, there are currently no (pattern-driven) Security methodologies specifically designed for general distributed systems. Going further, there are also currently no methodologies with mixed specific applicability, e.g. for both general and peer-to-peer distributed systems. In this paper we aim to fill these gaps by presenting a comprehensive pattern-driven Security Methodology – arrived at by applying a previously devised approach to engineering Security methodologies – specifically designed for general distributed systems, which is also capable of taking into account the specifics of peer-to-peer systems as needed. Our Methodology takes the principle of encapsulation several steps further, by employing patterns not only for the incorporation of Security features (via Security solution frames), but also for the modeling of threats, and even as part of its process. We illustrate and evaluate the presented Methodology in detail via a realistic example – the development of a distributed system for file sharing and collaborative editing. In both the presentation of the Methodology and example our focus is on the early life-cycle phases (analysis and design).

  • A comprehensive pattern-oriented approach to engineering Security methodologies
    Information and Software Technology, 2015
    Co-Authors: Anton V. Uzunov, Katrina Falkner, Eduardo B. Fernandez
    Abstract:

    Abstract Context Developing secure software systems is an issue of ever-growing importance. Researchers have generally come to acknowledge that to develop such systems successfully, their Security features must be incorporated in the context of a systematic approach: a Security Methodology. There are a number of such methodologies in the literature, but no single Security Methodology is adequate for every situation, requiring the construction of “fit-to-purpose” methodologies or the tailoring of existing methodologies to the project specifics at hand. While a large body of research exists addressing the same requirement for development methodologies – constituting the field of Method Engineering – there is nothing comparable for Security methodologies as such; in fact, the topic has never been studied before in such a context. Objective In this paper we draw inspiration from a number of Method Engineering ideas and fill the latter gap by proposing a comprehensive approach to engineering Security methodologies. Method Our approach is embodied in three interconnected parts: a framework of interrelated Security process patterns; a Security-specific meta-model; and a meta-Methodology to guide engineers in using the latter artefacts in a step-wise fashion. A UML-inspired notation is used for representing all pattern-based Methodology models during design and construction. The approach is illustrated and evaluated by tailoring an existing, real-life Security Methodology to a distributed-system-specific project situation. Results The paper proposes a novel pattern-oriented approach to modeling, constructing, tailoring and combining Security methodologies, which is the very first and currently sole such approach in the literature. We illustrate and evaluate our approach in an academic setting, and perform a feature analysis to highlight benefits and deficiencies. Conclusion Using our proposal, developers, architects and researchers can analyze and engineer Security methodologies in a structured, systematic fashion, taking into account all Security Methodology aspects.

  • Australian Software Engineering Conference - A Comprehensive Pattern-Driven Security Methodology for Distributed Systems
    2014 23rd Australian Software Engineering Conference, 2014
    Co-Authors: Anton V. Uzunov, Eduardo B. Fernandez, Katrina Falkner
    Abstract:

    Incorporating Security features is one of the most important and challenging tasks in designing distributed systems. Over the last decade, researchers and practitioners have come to recognize that the incorporation of Security features should proceed by means of a systematic approach, combining principles from both software and Security engineering. Such systematic approaches, particularly those implying some sort of process aligned with the development life-cycle, are termed Security methodologies. One of the most important classes of such methodologies is based on the use of Security patterns. While the literature presents a number of pattern-driven Security methodologies, none of them are designed specifically for general distributed systems. Going further, there are also currently no methodologies with mixed specific applicability, e.g. for both general and peer-to-peer distributed systems. In this paper we aim to fill these gaps by presenting a comprehensive pattern-driven Security Methodology specifically designed for general distributed systems, which is also capable of taking into account the specifics of peer-to-peer systems. Our Methodology takes the principle of encapsulation several steps further, by employing patterns not only for the incorporation of Security features (via Security solution frames), but also for the modeling of threats, and even as part of its process. We illustrate and evaluate the presented Methodology via a realistic example -- the development of a distributed system for file sharing and collaborative editing. In both the presentation of the Methodology and example our focus is on the early life-cycle phases (analysis and design).

Haralampos-g. Stratigopoulos - One of the best experts on this subject based on the ideXlab platform.

  • MixLock: Securing Mixed-Signal Circuits via Logic Locking
    2019
    Co-Authors: Julian Leonhard, Muhammad Yasin, Shadi Turk, Mohammed Nabeel, Marie-minerve Louërat, Roselyne Chotin-avot, Hassan Aboushady, Ozgur Sinanoglu, Haralampos-g. Stratigopoulos
    Abstract:

    In this paper, we propose a hardware Security Methodology for mixed-signal Integrated Circuits (ICs). The proposed Methodology can be used as a countermeasure for IC piracy, including counterfeiting and reverse engineering. It relies on logic locking of the digital section of the mixed-signal IC, such that unless the correct key is provided, the mixed-signal performance will be pushed outside of the acceptable specification range. We employ a state-of-the-art logic locking technique, called Stripped Functionality Logic Locking (SFLL). We show that strong Security levels are achieved in both mixed-signal and digital domains. In addition, the proposed Methodology presents several appealing properties. It is non-intrusive for the analog section, it incurs reasonable area and power overhead, it can be fully automated, and it is virtually applicable to a wide range of mixed-signal ICs. We demonstrate it on a Σ∆ Analog-to-Digital Converter (ADC).

  • DATE - MixLock: Securing Mixed-Signal Circuits via Logic Locking
    2019 Design Automation & Test in Europe Conference & Exhibition (DATE), 2019
    Co-Authors: Julian Leonhard, Muhammad Yasin, Shadi Turk, Mohammed Nabeel, Marie-minerve Louërat, Roselyne Chotin-avot, Hassan Aboushady, Ozgur Sinanoglu, Haralampos-g. Stratigopoulos
    Abstract:

    In this paper, we propose a hardware Security Methodology for mixed-signal Integrated Circuits (ICs). The proposed Methodology can be used as a countermeasure for IC piracy, including counterfeiting and reverse engineering. It relies on logic locking of the digital section of the mixed-signal IC, such that unless the correct key is provided, the mixed-signal performance will be pushed outside of the acceptable specification range. We employ a state-of-the-art logic locking technique, called Stripped Functionality Logic Locking (SFLL). We show that strong Security levels are achieved in both mixed-signal and digital domains. In addition, the proposed Methodology presents several appealing properties. It is non-intrusive for the analog section, it incurs reasonable area and power overhead, it can be fully automated, and it is virtually applicable to a wide range of mixed-signal ICs. We demonstrate it on a ΣΔ Analog-to-Digital Converter (ADC).