S-Scrum: a secure methodology for agile development of web services
To care for security in early stages of software development has always been a major engineering trend. However, due to the existence of unpreventable and accidental security faults within the system, it is not always possible to entirely identify and mitigate the security threats. This may eventual...
Saved in:
Main Authors: | , , |
---|---|
Format: | Article |
Language: | English |
Published: |
WCSIT Publishing
2013
|
Online Access: | http://psasir.upm.edu.my/id/eprint/30667/1/S.pdf http://psasir.upm.edu.my/id/eprint/30667/ http://download.wcsit.org/3.1.2013 |
Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Institution: | Universiti Putra Malaysia |
Language: | English |
id |
my.upm.eprints.30667 |
---|---|
record_format |
eprints |
spelling |
my.upm.eprints.306672017-10-31T02:10:37Z http://psasir.upm.edu.my/id/eprint/30667/ S-Scrum: a secure methodology for agile development of web services Mougouei, Davoud Mohd Sani, Nor Fazlida Almasi, Mohammad Moein To care for security in early stages of software development has always been a major engineering trend. However, due to the existence of unpreventable and accidental security faults within the system, it is not always possible to entirely identify and mitigate the security threats. This may eventually lead to security failure of the target system. To avoid security failure, it is required to incorporate fault tolerance (i.e. intrusion tolerant) into the security requirements of the system. In this paper, we propose a new technique toward description of security requirements of Intrusion Tolerant Systems (ITS) using fuzzy logic. We care for intrusion tolerance in security requirements of the system through considering partial satisfaction of security goals. This partiality is accepted and formally described through establishment of a Goal-Based Fuzzy Grammar (GFG) and its respective Goal-Based Fuzzy Language (GFL) for describing Security Requirement Model (SRM) of the target ITS. WCSIT Publishing 2013 Article PeerReviewed application/pdf en http://psasir.upm.edu.my/id/eprint/30667/1/S.pdf Mougouei, Davoud and Mohd Sani, Nor Fazlida and Almasi, Mohammad Moein (2013) S-Scrum: a secure methodology for agile development of web services. World of Computer Science and Information Technology Journal, 3 (1). pp. 15-19. ISSN 2221-0741 http://download.wcsit.org/3.1.2013 |
institution |
Universiti Putra Malaysia |
building |
UPM Library |
collection |
Institutional Repository |
continent |
Asia |
country |
Malaysia |
content_provider |
Universiti Putra Malaysia |
content_source |
UPM Institutional Repository |
url_provider |
http://psasir.upm.edu.my/ |
language |
English |
description |
To care for security in early stages of software development has always been a major engineering trend. However, due to the existence of unpreventable and accidental security faults within the system, it is not always possible to entirely identify and mitigate the security threats. This may eventually lead to security failure of the target system. To avoid security failure, it is required to incorporate fault tolerance (i.e. intrusion tolerant) into the security requirements of the system. In this paper, we propose a new technique toward description of security requirements of Intrusion Tolerant Systems (ITS) using fuzzy logic. We care for intrusion tolerance in security requirements of the system through considering partial satisfaction of security goals. This partiality is accepted and formally described through establishment of a Goal-Based Fuzzy Grammar (GFG) and its respective Goal-Based Fuzzy Language (GFL) for describing Security Requirement Model (SRM) of the target ITS. |
format |
Article |
author |
Mougouei, Davoud Mohd Sani, Nor Fazlida Almasi, Mohammad Moein |
spellingShingle |
Mougouei, Davoud Mohd Sani, Nor Fazlida Almasi, Mohammad Moein S-Scrum: a secure methodology for agile development of web services |
author_facet |
Mougouei, Davoud Mohd Sani, Nor Fazlida Almasi, Mohammad Moein |
author_sort |
Mougouei, Davoud |
title |
S-Scrum: a secure methodology for agile development of web services |
title_short |
S-Scrum: a secure methodology for agile development of web services |
title_full |
S-Scrum: a secure methodology for agile development of web services |
title_fullStr |
S-Scrum: a secure methodology for agile development of web services |
title_full_unstemmed |
S-Scrum: a secure methodology for agile development of web services |
title_sort |
s-scrum: a secure methodology for agile development of web services |
publisher |
WCSIT Publishing |
publishDate |
2013 |
url |
http://psasir.upm.edu.my/id/eprint/30667/1/S.pdf http://psasir.upm.edu.my/id/eprint/30667/ http://download.wcsit.org/3.1.2013 |
_version_ |
1643830127908356096 |