Security
by
Benedikt Liegener
—
last modified
Jul 13, 2011 15:10
—
filed under:
QualityAttribute,
KnowledgeModel
Definitions
| Term: Security |
Domain: Cross-cutting issues | ||||
|---|---|---|---|---|---|
| Engineering and Design (KM-ED) |
Adaptation and Monitoring (KM-AM) |
Quality Definition, Negotiation and
Assurance (KM-QA) |
Generic (domain independent) |
||
| D o m a i n : L a y e r s |
Business Process Management (KM-BPM) |
||||
| Service Composition and
Coordination (KM-SC) |
|||||
| Service Infrastructure (KM-SI) |
|||||
| Generic (domain independent) |
Security is the protection of both a computer system
and its data against unauthorized access, alteration or denial of use –
i.e. occurring contrary to the desire of the person who controls the
information, or the constraints supposedly enforced by the system even
though the intruder may be an otherwise legitimate user of the
computer. [Saltzer, Schroeder, 1975] Security for services ([Lee et al. 2003], [Shuping 2003], [Kritikos 2008]) means providing authentication,authorization, confidentiality,traceability/auditability, accountability, data encryption, and non-repudiation. Besides these classical quality attributes, there were added two more, namely safety and integrity. [Avizienis et al. 2001] {GEN: Quality Attribute}{SPC: Safety, Authorization, Authentication, Confidentiality, Integrity, Accountability, Traceability, Auditability, Data Encryption,Non-Repudation} |
||||
Competencies
- POLIMI: Security; http://www.dei.polimi.it/; Maria
Grazia Fugini
Scenarios
TBD
References
- [Avizienis et al. 2001] Algirdas Avizienis, Jean-Clause Laprie, and Brian Randell. Fundamental concepts of dependability. Technical Report 0100, Computer Science Department, University of California, Los Angeles, LA, USA, 2001
- [Kritikos 2008] Kyriakos Kritikos. Qos-based web service
description and discovery. Phd thesis, Computer Science Department,
University of Crete, Heraklion, Greece, 2008.
- [Lee et al. 2003] KangChan Lee, JongHong Jeon, WonSeok Lee,
Seong-Ho Jeong, and Sang-Won Park. Qos for web services: Requirements
and possible approaches. World Wide Web Consortium (W3C) note, November
2003.
- [Saltzer, Schroeder, 1975] J. H. Saltzer, and M.D. Schroeder, "The Protection of Information in Computer Systems", April 1975.
- [Shuping 2003] Shuping Ran. A model for web services discovery with qos. SIGecom Exch., 4(1):1–10, 2003.
- [Dessì et al. 2008] N. Dessì, M.G. Fugini, R. A. Balachandar,
“Policies and Security Aspects for Distributed Scientific
Laboratories”, IFIP SEC’2008 Conference, IFIP World Computer Congress,
Milano, Sept. 7-10, 2008.













