Show simple item record

dc.contributor.authorHayati, P.
dc.contributor.authorJafari, N.
dc.contributor.authorRezaei, S. M.
dc.contributor.authorSarenche, S.
dc.contributor.authorPotdar, Vidyasagar
dc.contributor.editorFarookh Hussain
dc.contributor.editorElizabeth Chang
dc.date.accessioned2017-01-30T11:19:57Z
dc.date.available2017-01-30T11:19:57Z
dc.date.created2009-03-23T18:01:07Z
dc.date.issued2008
dc.identifier.citationHayati, Pedram and Jafari, Nastaran and Rezaei, S mohammad and Sarenche, Saeed and Potdar, Vidyasagar. 2008. Modeling input validation in UML, in Farookh Hussain and Elizabeth Chang (ed), 19th Australian Software Engineering Conference (ASWEC 2008), Mar 25 2008, pp. 663-672.Perth, Australia: IEEE Computer Society
dc.identifier.urihttp://hdl.handle.net/20.500.11937/10625
dc.identifier.doi10.1109/ASWEC.2008.4483260
dc.description.abstract

Security is an integral part of most software systems but it is not considered as an explicit part in the development process yet. Input validation is the most critical part ofsoftware security that is not covered in the design phase of software development life-cycle resulting in many security vulnerabilities. Our objective is to extend UML to new integrated jramework for model driven security engineering leading to ideal way to design more secure software. Input validation in UML has not been addressed previously, hence we incorporate input validation into UML diagrams such as use case, class, sequence and activity. This approach has some advantages such as preventing jrom common input tampering attacks, having both security and convenience in software at high level of abstraction and ability of solving the problem ofweak security backgroundfor developers.

dc.publisherIEEE Computer Society
dc.titleModeling input validation in UML
dc.typeConference Paper
dcterms.source.startPage663
dcterms.source.endPage672
dcterms.source.issn15300803
dcterms.source.titleProceedings of the 19th Australian software engineering conference (ASWEC 2008)
dcterms.source.seriesProceedings of the 19th Australian software engineering conference (ASWEC 2008)
dcterms.source.conference19th Australian Software Engineering Conference (ASWEC 2008)
dcterms.source.conference-start-dateMar 25 2008
dcterms.source.conferencelocationPerth, Australia
dcterms.source.placeAustralia
curtin.note

Copyright © 2008 IEEE

curtin.note

This material is presented to ensure timely dissemination of scholarly and technical work. Copyright and all rights therein are retained by authors or by other copyright holders. All persons copying this information are expected to adhere to the terms and constraints invoked by each author's copyright. In most cases, these works may not be reposted without the explicit permission of the copyright holder.

curtin.departmentCentre for Extended Enterprises and Business Intelligence
curtin.accessStatusOpen access


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record