Using Aspects to Manage Security Risks in Risk-Driven Development

Siv Hilde Houmb, Geri Georg, Dan Matheson · 2004

Abstract. The EU IST-project CORAS has developed an integrated risk management and system development process for security-critical systems based on AS/NZS 4360, RUP, and RM–ODP. The approach presented in this paper is based on the concepts of risk-driven development and extends the CORAS framework by using aspects to specify security risk treatment options. This enhances the evaluation of the treatment options since aspects models are decoupled from the primary model. The result is an aspect-oriented risk-driven development approach, in which security requirements or security risks may be identified in each phase of the development. The treatments that addresses these requirements or security risks are specified and implemented as aspects. Using aspects makes it easier to develop and evaluate security treatments options and to evolve the treatments. Keywords:Risk-driven development (RDD), Aspect-oriented modeling (AOM), Security risk assessment, and Trade-off analysis 1

Read the paper · More papers on PaperTik