Towards a model-driven security assurance of open source components

  • Irum Rauf
  • , Elena Troubitsyna

Research output: Chapter in Book/Report/Conference proceedingsChapterpeer-review

Abstract

Open Source software is increasingly used in a wide spectrum of applications. While the benefits of the open source components are unquestionable now, there is a great concern over security assurance provided by such components. Often open source software is a subject of frequent updates. The updates might introduce or remove a diverse range of features and hence violate security properties of the previous releases. Obviously, a manual inspection of security would be prohibitively slow and inefficient. Therefore, there is a great demand for the techniques that would allow the developers to automate the process of security assurance in the presence of frequent releases. The problem of security assurance is especially challenging because to ensure scalability, such main open source initiatives, as OpenStack adopt RESTful architecture. This requires new security assurance techniques to cater to stateless nature of the system. In this paper, we propose a model-driven framework that would allow the designers to model the security concerns and facilitate verification and validation of them in an automated manner. It enables a regular monitoring of the security features even in the presence of frequent updates. We exemplify our approach with the Keystone component of OpenStack.

Original languageEnglish
Title of host publicationSoftware Engineering for Resilient Systems - 9th International Workshop, SERENE 2017, Proceedings
EditorsAlexander Romanovsky, Elena A. Troubitsyna
PublisherSpringer Verlag
Pages65-80
Number of pages16
ISBN (Print)9783319659473
DOIs
Publication statusPublished - 2017
Externally publishedYes
Event9th International Workshop on Software Engineering for Resilient Systems, SERENE 2017 - Geneva, Switzerland
Duration: 4 Sep 20175 Sep 2017

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume10479 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference9th International Workshop on Software Engineering for Resilient Systems, SERENE 2017
Country/TerritorySwitzerland
CityGeneva
Period4/09/175/09/17

Fingerprint

Dive into the research topics of 'Towards a model-driven security assurance of open source components'. Together they form a unique fingerprint.

Cite this