The Experts below are selected from a list of 3036 Experts worldwide ranked by ideXlab platform

Eduardo B. Fernandez - One of the best experts on this subject based on the ideXlab platform.

  • a pattern driven Security Process for soa applications
    ACM Symposium on Applied Computing, 2008
    Co-Authors: Nelly A. Delessy, Eduardo B. Fernandez
    Abstract:

    SOA enables the design of flexible and modular software applications that can be used in a cross-organization context. Unfortunately, those qualities have a negative impact on the Security of the software application. In this paper, we provide an approach to build secure SOA applications that takes into account the new Security issues introduced by the complexity of SOA-based applications. We build upon two different approaches to secure SOA applications: model-driven development and the use of Security patterns.

  • SAC - A pattern-driven Security Process for SOA applications
    Proceedings of the 2008 ACM symposium on Applied computing - SAC '08, 2008
    Co-Authors: Nelly A. Delessy, Eduardo B. Fernandez
    Abstract:

    SOA enables the design of flexible and modular software applications that can be used in a cross-organization context. Unfortunately, those qualities have a negative impact on the Security of the software application. In this paper, we provide an approach to build secure SOA applications that takes into account the new Security issues introduced by the complexity of SOA-based applications. We build upon two different approaches to secure SOA applications: model-driven development and the use of Security patterns.

  • A Pattern-Driven Security Process for SOA Applications
    2008 Third International Conference on Availability Reliability and Security, 2008
    Co-Authors: Nelly A. Delessy, Eduardo B. Fernandez
    Abstract:

    SOA enables the design of flexible and modular software applications that can be used in a cross- organization context. Unfortunately, those qualities have a negative impact on the Security of the software application. In this paper, we investigate the production of secure SOA applications. In particular, we provide an approach to build secure SOA applications that takes into account the new Security issues introduced by the complexity of SOA-based applications. We build upon two different approaches to secure SOA applications: model-driven development and the use of Security patterns.

  • ARES - A Pattern-Driven Security Process for SOA Applications
    2008 Third International Conference on Availability Reliability and Security, 2008
    Co-Authors: Nelly A. Delessy, Eduardo B. Fernandez
    Abstract:

    SOA enables the design of flexible and modular software applications that can be used in a cross- organization context. Unfortunately, those qualities have a negative impact on the Security of the software application. In this paper, we investigate the production of secure SOA applications. In particular, we provide an approach to build secure SOA applications that takes into account the new Security issues introduced by the complexity of SOA-based applications. We build upon two different approaches to secure SOA applications: model-driven development and the use of Security patterns.

Nelly A. Delessy - One of the best experts on this subject based on the ideXlab platform.

  • a pattern driven Security Process for soa applications
    ACM Symposium on Applied Computing, 2008
    Co-Authors: Nelly A. Delessy, Eduardo B. Fernandez
    Abstract:

    SOA enables the design of flexible and modular software applications that can be used in a cross-organization context. Unfortunately, those qualities have a negative impact on the Security of the software application. In this paper, we provide an approach to build secure SOA applications that takes into account the new Security issues introduced by the complexity of SOA-based applications. We build upon two different approaches to secure SOA applications: model-driven development and the use of Security patterns.

  • SAC - A pattern-driven Security Process for SOA applications
    Proceedings of the 2008 ACM symposium on Applied computing - SAC '08, 2008
    Co-Authors: Nelly A. Delessy, Eduardo B. Fernandez
    Abstract:

    SOA enables the design of flexible and modular software applications that can be used in a cross-organization context. Unfortunately, those qualities have a negative impact on the Security of the software application. In this paper, we provide an approach to build secure SOA applications that takes into account the new Security issues introduced by the complexity of SOA-based applications. We build upon two different approaches to secure SOA applications: model-driven development and the use of Security patterns.

  • A Pattern-Driven Security Process for SOA Applications
    2008 Third International Conference on Availability Reliability and Security, 2008
    Co-Authors: Nelly A. Delessy, Eduardo B. Fernandez
    Abstract:

    SOA enables the design of flexible and modular software applications that can be used in a cross- organization context. Unfortunately, those qualities have a negative impact on the Security of the software application. In this paper, we investigate the production of secure SOA applications. In particular, we provide an approach to build secure SOA applications that takes into account the new Security issues introduced by the complexity of SOA-based applications. We build upon two different approaches to secure SOA applications: model-driven development and the use of Security patterns.

  • ARES - A Pattern-Driven Security Process for SOA Applications
    2008 Third International Conference on Availability Reliability and Security, 2008
    Co-Authors: Nelly A. Delessy, Eduardo B. Fernandez
    Abstract:

    SOA enables the design of flexible and modular software applications that can be used in a cross- organization context. Unfortunately, those qualities have a negative impact on the Security of the software application. In this paper, we investigate the production of secure SOA applications. In particular, we provide an approach to build secure SOA applications that takes into account the new Security issues introduced by the complexity of SOA-based applications. We build upon two different approaches to secure SOA applications: model-driven development and the use of Security patterns.

Andrew Fish - One of the best experts on this subject based on the ideXlab platform.

  • Enhancing secure business Process design with Security Process patterns
    Software & Systems Modeling, 2019
    Co-Authors: Nikolaos Argyropoulos, Haralambos Mouratidis, Andrew Fish
    Abstract:

    Business Process definition and analysis are an important activity for any organisation. As research has demonstrated, well-defined business Processes can reduce cost, improve productivity and provide organisations with competitive advantages. In the last few years, the need to ensure the Security of business Processes has been identified as a major research challenge. Limited Security expertise of business Process developers together with a clear lack of appropriate methods and techniques to support the Security analysis of business Processes is important prohibitors to providing answers to that research challenge. This paper introduces the first attempt in the literature to produce a novel pattern-based approach to support the design and analysis of secure business Processes. Our work draws on elements from the Security requirements engineering area and the Security patterns area, combined with business Process modelling, and it produces a set of Process-level Security patterns which are used to implement Security in a given business Process model. Such an approach advances the existing literature by providing a structured way of operationalising Security at the business Process level of abstraction. The applicability of the work is illustrated through an application to a real-life information system, and the effectiveness and usability of the work are evaluated via a workshop-based experiment. The evaluation clearly indicates that non-experts are able to comprehend and utilise the developed patterns to construct secure business Process designs.

  • Supporting secure business Process design via Security Process patterns
    Lecture Notes in Business Information Processing, 2017
    Co-Authors: Nikolaos Argyropoulos, Haralambos Mouratidis, Andrew Fish
    Abstract:

    Security is an important non-functional characteristic of the business Processes used by organisations for the coordination of their activities. Nevertheless, the implementation of Security at the operational level can be challenging due to the limited Security expertise of Process designers and the delayed consideration of Security during Process development. To overcome such issues, expert knowledge and proven Security solutions can be captured in the form of Process patterns, which can easily be reused and integrated to business Processes with minimal Security-related knowledge required. In this work we introduce Process-level Security patterns, each of which contains the main activities required for the operationalisation of different Security requirements. The introduced patterns are then used as a component of an existing framework for the creation of secure business Process designs, the application of which, is illustrated through a working example. A preliminary evaluation of the proposed patterns is conducted via a workshop session.

Nikolaos Argyropoulos - One of the best experts on this subject based on the ideXlab platform.

  • Enhancing secure business Process design with Security Process patterns
    Software & Systems Modeling, 2019
    Co-Authors: Nikolaos Argyropoulos, Haralambos Mouratidis, Andrew Fish
    Abstract:

    Business Process definition and analysis are an important activity for any organisation. As research has demonstrated, well-defined business Processes can reduce cost, improve productivity and provide organisations with competitive advantages. In the last few years, the need to ensure the Security of business Processes has been identified as a major research challenge. Limited Security expertise of business Process developers together with a clear lack of appropriate methods and techniques to support the Security analysis of business Processes is important prohibitors to providing answers to that research challenge. This paper introduces the first attempt in the literature to produce a novel pattern-based approach to support the design and analysis of secure business Processes. Our work draws on elements from the Security requirements engineering area and the Security patterns area, combined with business Process modelling, and it produces a set of Process-level Security patterns which are used to implement Security in a given business Process model. Such an approach advances the existing literature by providing a structured way of operationalising Security at the business Process level of abstraction. The applicability of the work is illustrated through an application to a real-life information system, and the effectiveness and usability of the work are evaluated via a workshop-based experiment. The evaluation clearly indicates that non-experts are able to comprehend and utilise the developed patterns to construct secure business Process designs.

  • Supporting secure business Process design via Security Process patterns
    Lecture Notes in Business Information Processing, 2017
    Co-Authors: Nikolaos Argyropoulos, Haralambos Mouratidis, Andrew Fish
    Abstract:

    Security is an important non-functional characteristic of the business Processes used by organisations for the coordination of their activities. Nevertheless, the implementation of Security at the operational level can be challenging due to the limited Security expertise of Process designers and the delayed consideration of Security during Process development. To overcome such issues, expert knowledge and proven Security solutions can be captured in the form of Process patterns, which can easily be reused and integrated to business Processes with minimal Security-related knowledge required. In this work we introduce Process-level Security patterns, each of which contains the main activities required for the operationalisation of different Security requirements. The introduced patterns are then used as a component of an existing framework for the creation of secure business Process designs, the application of which, is illustrated through a working example. A preliminary evaluation of the proposed patterns is conducted via a workshop session.

Haralambos Mouratidis - One of the best experts on this subject based on the ideXlab platform.

  • Enhancing secure business Process design with Security Process patterns
    Software & Systems Modeling, 2019
    Co-Authors: Nikolaos Argyropoulos, Haralambos Mouratidis, Andrew Fish
    Abstract:

    Business Process definition and analysis are an important activity for any organisation. As research has demonstrated, well-defined business Processes can reduce cost, improve productivity and provide organisations with competitive advantages. In the last few years, the need to ensure the Security of business Processes has been identified as a major research challenge. Limited Security expertise of business Process developers together with a clear lack of appropriate methods and techniques to support the Security analysis of business Processes is important prohibitors to providing answers to that research challenge. This paper introduces the first attempt in the literature to produce a novel pattern-based approach to support the design and analysis of secure business Processes. Our work draws on elements from the Security requirements engineering area and the Security patterns area, combined with business Process modelling, and it produces a set of Process-level Security patterns which are used to implement Security in a given business Process model. Such an approach advances the existing literature by providing a structured way of operationalising Security at the business Process level of abstraction. The applicability of the work is illustrated through an application to a real-life information system, and the effectiveness and usability of the work are evaluated via a workshop-based experiment. The evaluation clearly indicates that non-experts are able to comprehend and utilise the developed patterns to construct secure business Process designs.

  • Supporting secure business Process design via Security Process patterns
    Lecture Notes in Business Information Processing, 2017
    Co-Authors: Nikolaos Argyropoulos, Haralambos Mouratidis, Andrew Fish
    Abstract:

    Security is an important non-functional characteristic of the business Processes used by organisations for the coordination of their activities. Nevertheless, the implementation of Security at the operational level can be challenging due to the limited Security expertise of Process designers and the delayed consideration of Security during Process development. To overcome such issues, expert knowledge and proven Security solutions can be captured in the form of Process patterns, which can easily be reused and integrated to business Processes with minimal Security-related knowledge required. In this work we introduce Process-level Security patterns, each of which contains the main activities required for the operationalisation of different Security requirements. The introduced patterns are then used as a component of an existing framework for the creation of secure business Process designs, the application of which, is illustrated through a working example. A preliminary evaluation of the proposed patterns is conducted via a workshop session.

  • Advanced Information Systems Engineering
    2014
    Co-Authors: Matthias Jarke, Haralambos Mouratidis, John Mylopoulos, Christoph Quix, Colette Rolland, Yannis Manopoulos, Jennifer Horkoff
    Abstract:

    This book constitutes the proceedings of 26th International Conference on Advanced Information Systems Engineering, CAiSE 2014, held in Thessaloniki, Greece in June 2014. The 41 papers and 3 keynotes presented were carefully reviewed and selected from 226 submissions. The accepted papers were presented in 13 sessions: clouds and services; requirements; product lines; requirements elicitation; Processes; risk and Security; Process models; data mining and streaming; Process mining; models; mining event logs; databases; software engineering.