Computer ScienceEngineering

Security Requirements Elaborations for Grid Data Management Systems

S. Naqvi, C. Ponsard, Philippe Massonet, Á. Arenas

2008International Journal of System of Systems Engineering

tlooto Summary

A goal-oriented approach to design policies for managing security requirements of critical information infrastructures (CII), adapted from a standard and widely accepted requirements engineering methodology, is applied to the security analysis of a specific CII: Grid Data Management Systems (GDMS).

Abstract

In this paper, we present a goal-oriented approach to design policies for managing security requirements of critical information infrastructures (CII). The approach, adapted from a standard and widely accepted requirements engineering methodology, is applied to the security analysis of a specific CII: Grid Data Management Systems (GDMS). Based on domain ontologies, combining concepts borrowed both from Virtual Organisation and Secure UML, a comprehensive set of GDMS security requirements is elicited and structured first semi-formally then formally. The benefits of the early formalisation are illustrated in term of completeness and consistency. A specific security analysis, using anti-goals, is also performed on the resulting formal security model to address the presence of malicious agents. Derivation of security policy from the set of security requirements is performed, first based on an abstract operationalization, still in the problem domain, and then it is translated into more concrete policy templates using standard policy constructs. Perspectives of the policy refinement and translation on existing policy languages and frameworks are described for its low-level implementation.

Citation format

NAQVI, S., et al. Security requirements elaborations for grid data management systems. International Journal of System of Systems Engineering, 2008.