Specification and management of security requirements for service-based systems
Zhaoji Chen · 2008
The major advantages of service-based systems are their flexibility and the ability to enable rapid development of large-scale distributed systems achieving various system goals by finding and composing available services. The services can be independently developed using different program languages and deployed over various platforms across multiple domains. In order to support such seamless integration of services, in addition to service matching and indexing, techniques need to be developed for systematic security requirement specification and management when individual services are composed together. So far, there is no approach that can capture all the essential security requirements of service-based systems, support redundancy and conflict detection, provide security requirement adaptation, as well as facilitate conflict reconciliation. In this dissertation, a framework is presented for systematically specifying and managing security requirements for service-based systems with many advanced features. The framework uses the Security Requirement Specification Language (SRSL) to specify unambiguous interoperable security requirements based on a security requirement ontology which models essential elements of security requirements in service-based systems. Logic reasoning rules are developed based on the semantic meanings embedded in security requirement specifications, and algorithms are developed to automatically derive security constraints, unify vocabularies used in the security requirement specifications as well as perform redundancy and conflict checking. A similarity-based security requirement adaptation algorithm is developed for adapting existing security requirements to address the expanded set of users resulted by service compositions. Finally a negotiation protocol is presented to reconcile conflicting security requirements detected during the security analysis. With all the support each component provides, this framework improves the ability and efficiency for users to specify and manage security requirements for service-based systems, and provides users the level of assurance that is needed for service-based systems to be widely adopted for mission critical applications.