DC Field | Value | Language |
dc.contributor.author | Brazhuk, A. | - |
dc.contributor.author | Olizarovich, E. | - |
dc.date.accessioned | 2021-11-04T06:36:27Z | - |
dc.date.available | 2021-11-04T06:36:27Z | - |
dc.date.issued | 2021 | - |
dc.identifier.citation | Brazhuk, A. Contextualizing of Architectural Security Patterns as a Knowledge Management Challenge / Brazhuk A., Olizarovich E. // Pattern Recognition and Information Processing (PRIP'2021) = Распознавание образов и обработка информации (2021) : Proceedings of the 15th International Conference, 21–24 Sept. 2021, Minsk, Belarus / United Institute of Informatics Problems of the National Academy of Sciences of Belarus. – Minsk, 2021. – P. 101–105. | ru_RU |
dc.identifier.uri | https://libeldoc.bsuir.by/handle/123456789/45779 | - |
dc.description.abstract | Security-by-design as adoption of security solutions for a system design is in focus of this work. This field is treated as requiring expert knowledge and heavy for automation. A perspective way to improve exiting security design methodologies is the use of security patterns as a mechanism of collecting secure design artifacts. To apply security patterns as a part of automation of secure design, it requires well-formed collections of security patterns and innovative method to support the design decisions. This work considers a contextualizing challenge as a way to define the necessity of a security pattern in a given case. Understanding of context includes two main questions: "Is the security pattern suitable for a system design?" and "Does the security pattern affect a particular security challenge?". We approach a direct architectural contextualizing as a basic mechanism of automatic mapping of security artifacts (threats, security solutions) to components of a
computer system during early design stages (requirements, design). Also, this work describes two use cases of the architectural contextualizing based on an ontological cloud threat pattern catalog: the use of a query language for finding relevant security patterns and analysis of graphical system representations based on an ontology driven threat modeling. This work uses a strict ontological approach, implemented with Web Ontology Language (OWL) and automatic reasoning procedures. | ru_RU |
dc.language.iso | en | ru_RU |
dc.publisher | UIIP NASB | ru_RU |
dc.subject | материалы конференций | ru_RU |
dc.subject | conference proceedings | ru_RU |
dc.subject | security pattern | ru_RU |
dc.subject | ontology | ru_RU |
dc.subject | contextualizing | ru_RU |
dc.subject | threat modeling | ru_RU |
dc.subject | OWL | ru_RU |
dc.title | Contextualizing of Architectural Security Patterns as a Knowledge Management Challenge | ru_RU |
dc.type | Статья | ru_RU |
Appears in Collections: | Pattern Recognition and Information Processing (PRIP'2021) = Распознавание образов и обработка информации (2021)
|