Modeling input validation in UML
Access Status
Authors
Date
2008Type
Metadata
Show full item recordCitation
Source Title
Source Conference
ISSN
School
Remarks
Copyright © 2008 IEEE
This material is presented to ensure timely dissemination of scholarly and technical work. Copyright and all rights therein are retained by authors or by other copyright holders. All persons copying this information are expected to adhere to the terms and constraints invoked by each author's copyright. In most cases, these works may not be reposted without the explicit permission of the copyright holder.
Collection
Abstract
Security is an integral part of most software systems but it is not considered as an explicit part in the development process yet. Input validation is the most critical part ofsoftware security that is not covered in the design phase of software development life-cycle resulting in many security vulnerabilities. Our objective is to extend UML to new integrated jramework for model driven security engineering leading to ideal way to design more secure software. Input validation in UML has not been addressed previously, hence we incorporate input validation into UML diagrams such as use case, class, sequence and activity. This approach has some advantages such as preventing jrom common input tampering attacks, having both security and convenience in software at high level of abstraction and ability of solving the problem ofweak security backgroundfor developers.
Related items
Showing items related by title, author, creator and subject.
-
Marinelli, Marco Antonio (2011)Important economic and environmental decisions are routinely based on spatial/ temporal models. This thesis studies the uncertainty in the predictions of three such models caused by uncertainty propagation. This is ...
-
To, Lap C. (1996)Nonlinearities exist in all process control systems. The use of linear control techniques is valid only in a narrow range of operation. Therefore, in this thesis, multivariable nonlinear control techniques are considered. ...
-
Sullivan, Michael R. (2003)This dissertation applies a commercial flow simulation software package together with common signal processing techniques to the task of accurately detecting leakage in a large commercial gas pipeline. The techniques ...