Security Oriented Malicious Activity Diagrams to Support Information Systems Security
Othmar Othmar Mwambe, Isao Echizen · 2017
This study focuses on supporting information systems security in the early phase of information systems development. Modeling languages have commonly been used by software developers during the designing of information systems. As an extension of Unified Modeling Language (UML) activity diagrams, Mal-Activity Diagrams (MAD) have also been used to model malicious and risk mitigation processes. Despite of its crucial role, MAD undergoes syntactic and semantic drawback which makes its Meta Model not being able to support key security features of its core security framework, information system security risk management domain model (ISSRM). To address this problem a scenario-based approach has been proposed using our new constructs and the output of the study is the modeling tool, comprehensive Meta Model for Security Oriented Malicious Activity Diagrams (SOMAD). The study has also elaborated the approach using clear example to elicit proper understanding of the concept.