Validation of a security metamodel for development of cloud applications
Marcos Arjona, Carolina Dania, Marina Egea, Antonio Maña · 2015
Abstract. Development of secure cloud applications requires a supportive ap-proach that should also enable software assessment and certification by different mechanisms. These can assure by independent means that the required security is present. In this paper we present a Core Security Metamodel (CSM) that is the director of a security engineering process that also addresses security certi-fication for cloud applications. To drive these activities with enough precision, the CSM is constrained with OCL rules that control the creation of instances of the metamodel. Due to their relevance for the security engineering process, we decided to formally check their consistency leveraging on our previous mapping from OCL to First Order Logic. We found that CVC4 returned sat in less than 30 seconds when we run it in finite model finder mode. Also, it automatically provided a valid CSM structural instance. Instances so obtained with CVC4 can be tuned to serve as input of the engineering process of secure cloud applications. Their automatic generation reduces the time and effort spent in the engineering process, reinforcing its supportive and practical side. 1