Modelling, validating, and ranking of secure service compositions
Achim D. Brucker, Bo Zhou, Francesco Malmignati, Qi Shi, Madjid Merabti · Software Practice and Experience · 2017
Summary In the world of large‐scale applications, software as a service (SaaS) in general and use of microservices, in particular, is bringing service‐oriented architectures to a new level: Systems in general and systems that interact with human users (eg, sociotechnical systems) in particular are built by composing microservices that are developed independently and operated by different parties. At the same time, SaaS applications are used more and more widely by enterprises as well as public services for providing critical services, including those processing security or privacy of relevant data. Therefore, providing secure and reliable service compositions is increasingly needed to ensure the success of SaaS solutions. Building such service compositions securely is still an unsolved problem. In this paper, we present a framework for modelling, validating, and ranking secure service compositions that integrate both automated services as well as services that interact with humans. As a unique feature, our approach for ranking services integratesvalidated properties(eg, based on the result of formally analysing the source code of a service implementation) as well ascontractual propertiesthat are part of the service level agreement and, thus, not necessarily ensured on a technical level.