OASIS: Weakening User Obligations for Security-critical Systems - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2020

OASIS: Weakening User Obligations for Security-critical Systems

Résumé

Security-critical systems typically place some requirements on the behaviour of their users, obliging them to follow certain instructions when using those systems. Security vulnerabilities can arise when users do not fully satisfy their obligations. In this paper, we propose an approach that improves system security by ensuring that attack scenarios are mitigated even when the users deviate from their expected behaviour. The approach uses structured transition systems to present and reason about user obligations. The aim is to identify potential vulnerabilities by weakening the assumptions on how the user will behave. We present an algorithm that combines iterative abstraction and controller synthesis to produce a new software specification that maintains the satisfaction of security requirements while weakening user obligations. We demonstrate the feasibility of our approach through two examples from the e-voting and e-commerce domains.
Fichier principal
Vignette du fichier
re_2020.pdf (594.19 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-02896256 , version 1 (10-07-2020)

Identifiants

  • HAL Id : hal-02896256 , version 1

Citer

Thein Than Tun, Amel Bennaceur, Bashar Nuseibeh. OASIS: Weakening User Obligations for Security-critical Systems. 28th IEEE International Requirements Engineering Conference, Aug 2020, Zurich, Switzerland. ⟨hal-02896256⟩
26 Consultations
83 Téléchargements

Partager

Gmail Facebook X LinkedIn More