The correct development of security-critical computer systems is as vital as it is difficult. This book presents the extension UMLsec of the Unified Modeling Language for secure systems development. The book is written in a way which keeps the first part (ch 1-5), describing UMLsec and ist use, acce
Secure Systems Development with UML
β Scribed by Jan JΓΌrjens (auth.)
- Publisher
- Springer-Verlag Berlin Heidelberg
- Year
- 2005
- Tongue
- English
- Leaves
- 317
- Edition
- 1
- Category
- Library
No coin nor oath required. For personal study only.
β¦ Synopsis
Attacks against computer systems can cause considerable economic or physical damage. High-quality development of security-critical systems is difficult, mainly because of the conflict between development costs and verifiable correctness.
JΓΌrjens presents the UML extension UMLsec for secure systems development. It uses the standard UML extension mechanisms, and can be employed to evaluate UML specifications for vulnerabilities using a formal semantics of a simplified fragment of UML. Established rules of security engineering can be encapsulated and hence made available even to developers who are not specialists in security. As one example, JΓΌrjens uncovers a flaw in the Common Electronic Purse Specification, and proposes and verifies a correction.
With a clear separation between the general description of his approach and its mathematical foundations, the book is ideally suited both for researchers and graduate students in UML or formal methods and security, and for advanced professionals writing critical applications.
β¦ Table of Contents
Introduction....Pages 3-14
Walk-through: Using UML for Security....Pages 15-20
Background....Pages 21-46
Model-based Security Engineering with UML....Pages 49-74
Applications....Pages 75-130
Tool support for UMLsec....Pages 133-160
A Formal Foundation....Pages 161-189
Formal Systems Development with UML....Pages 191-233
Further Material....Pages 237-242
Outlook....Pages 243-244
β¦ Subjects
Software Engineering; Management of Computing and Information Systems
π SIMILAR VOLUMES
SECTION ONE: INTRODUCTION AND CASE STUDIES -- Modelling and Notation The Unified Modelling Language -- Case Studies ICANDO Oil -- SECTION TWO: THE INTITIATION, ORGANISATION AND MANAGEMENT OF IT PROJECTS -- Project Conception and Initiation -- Software Development Lifecycle -- Managing the Process --
Covering the breadth of a large topic, this book provides a thorough grounding in object-oriented concepts, the software development process, UML and multi-tier technologies. After covering some basic ground work underpinning OO software projects, the book follows the steps of a typical developmen
Covering the breadth of a large topic, this book provides a thorough grounding in object-oriented concepts, the software development process, UML and multi-tier technologies.Β Β After covering some basic ground work underpinning OO software projects, the book follows the steps of a typical developmen