Support for Security Analysis of Design Models based on Traceability

Hirokazu Yatsu,Masaru Matsunami,Toshimi Sawada,Go Hirakawa,Atsushi Noda,Naoya Obata,Takahiro Ando,Kenji Hisazumi,Weiqiang Kong,Akira Fukuda
2015-01-01
Abstract:Software systems embedded into the foundation of information society is required to be secure. Requirements for the system to be secure should be properly recognized in the upper process of system development, and accurately reflected in their specifications and designs. However, security analysis to decide whether systems are secure or not is usually done at the implementation phase of system development or later. In this paper, we propose a universal approach to support security analysis at the design phase. Our approach is to detect vulnerable parts of systems based on traceability established among SysML diagrams, security threats and countermeasures against threats using SMT solvers.
What problem does this paper attempt to address?