Towards Security Awareness in Designing Service-Oriented Architectures - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2013

Towards Security Awareness in Designing Service-Oriented Architectures

Résumé

Many information security approaches deal with service-oriented architectures by focusing on security policies, requirements and technical implementation during service design, specification and implementation phases. Nevertheless, service-oriented architectures are increasingly deployed in open, distributed and dynamic environments, which particularly require an end-to-end security at each phase of the service’s lifecycle. Moreover, the security should not only focus on services without considering the risks and threats that might be caused by elements from business activities or underlying hardware and software infrastructure. In this paper, we develop a model highlighting the dependency between elements at business, service and infrastructure levels, defining the design context. In addition, we develop a holistic approach to define a security conceptual model, including services, security risks and security policies and guides all phases in a typical design method for service-oriented architectures.
Fichier non déposé

Dates et versions

hal-01339292 , version 1 (29-06-2016)

Identifiants

  • HAL Id : hal-01339292 , version 1

Citer

Pascal Bou Nassar, Youakim Badr, Frédérique Biennier, Kablan Barbar. Towards Security Awareness in Designing Service-Oriented Architectures. 16th International Conference on Enterprise Information Systems (ICEIS), Jul 2013, Angers, France. pp.377-385. ⟨hal-01339292⟩
67 Consultations
0 Téléchargements

Partager

Gmail Facebook X LinkedIn More