Towards a Reuse-oriented Security Engineering for Web-based Applications and Services
Aleksander Dikanski, Sebastian Abeck · Repository KITopen (Karlsruhe Institute of Technology) · 2012
Security should be considered throughout a software development process to develop secure applications. This security engineering effort is restricted due to the complexity and diffusion of todays security knowledge. Approaches, such as misuse cases for threat specification and patterns for security functionality modeling, try to use and integrate security into software development, but their combined use is still difficult. In this paper a framework for developing secure software systems is presented, which aims at incorporating and unifying existing security engineering approaches by applying well-established reuse-oriented software development paradigms, such as service-orientation. The security-related activities and reusable artifacts of important development phases are discussed and the mapping of artifacts between different development phases is presented. Keywords-security engineering; software development; security patterns; service-orientation