From What to How: A Taxonomy of Formalized Security Properties

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Sayar, Imen, Messe, Nan, Ebersold, Sophie, Bruel, Jean-Michel
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909617511989248
author Sayar, Imen
Messe, Nan
Ebersold, Sophie
Bruel, Jean-Michel
author_facet Sayar, Imen
Messe, Nan
Ebersold, Sophie
Bruel, Jean-Michel
contents Confidentiality, integrity, availability, authenticity, authorization, and accountability are known as security properties that secure systems should preserve. They are usually considered as security final goals that are achieved by system development activities, either in a direct or an indirect manner. However, these security properties are mainly elicited in the high-level requirement phase during the System Development Life Cycle (SDLC) and are not refined throughout the latter phases as other artifacts such as attacks, defenses, and system assets. To align security properties refinement with attacks, defenses, and system assets refinements, we propose an SDLC taxonomy of security properties that may be used in a self-adaptive context and present the methodology for defining it. To verify and check the correctness of the resulting taxonomy, we use the Event-B formal language.
format Preprint
id arxiv_https___arxiv_org_abs_2505_14514
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle From What to How: A Taxonomy of Formalized Security Properties
Sayar, Imen
Messe, Nan
Ebersold, Sophie
Bruel, Jean-Michel
Software Engineering
Confidentiality, integrity, availability, authenticity, authorization, and accountability are known as security properties that secure systems should preserve. They are usually considered as security final goals that are achieved by system development activities, either in a direct or an indirect manner. However, these security properties are mainly elicited in the high-level requirement phase during the System Development Life Cycle (SDLC) and are not refined throughout the latter phases as other artifacts such as attacks, defenses, and system assets. To align security properties refinement with attacks, defenses, and system assets refinements, we propose an SDLC taxonomy of security properties that may be used in a self-adaptive context and present the methodology for defining it. To verify and check the correctness of the resulting taxonomy, we use the Event-B formal language.
title From What to How: A Taxonomy of Formalized Security Properties
topic Software Engineering
url https://arxiv.org/abs/2505.14514