skip to main content
10.1145/1370905.1370908acmconferencesArticle/Chapter ViewAbstractPublication PagesicseConference Proceedingsconference-collections
research-article

From security patterns to implementation using petri nets

Published:17 May 2008Publication History

ABSTRACT

Security Patterns - the adaption of Design Patterns by Gamma et al. to security - have not quite met the expectations since Yoder and Barcalow pioneered the field. The two main reasons for this are the lack of formalisation and the fact that security often permeates all parts of a software, which is hard to encapsulate in a single pattern.

This paper investigates and presents our method of using Petri nets to first model security patterns on an abstract level. Gradual and intuitive refinement of the Petri nets then permits the creation of a running Petri net implementation - very much in the sense of model driven software engineering (MDSE) and model driven security (MDS). The Petri nets are modelled and executed using Renew - both IDE and virtual machine.

References

  1. C. Alexander. The timeless way of building. Oxford University Press, 1979.]]Google ScholarGoogle Scholar
  2. D. A. Basin, J. Doser, and T. Lodderstedt. Model driven security: From UML models to access control infrastructures. ACM Trans. Softw. Eng. Methodol., 15(1):39--91, 2006.]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  3. A. M. Braga, C. M. F. Rubira, and R. Dahab. Tropyc: A pattern language for cryptographic software. Technical Report IC--99--03, Institute of Computing, University of Campinas, Jan. 1999.]]Google ScholarGoogle Scholar
  4. L. Cabac, D. Moldt, and H. Rölke. A proposal for structuring Petri net--based agent interaction protocols. In W. v. d. Aalst and E. Best, editors, 24th International Conference on Application and Theory of Petri Nets, Eindhoven, Netherlands, June 2003, volume 2679 of LNCS, pages 102--120. Springer, June 2003.]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  5. L. Dai and K. Cooper. A survey of modeling and analysis approaches for architecting secure software systems. International Journal of Network Security, 5(2):187--198, Sept. 2007.]]Google ScholarGoogle Scholar
  6. M. Duvigneau. Bereitstellung einer Agentenplattform für petrinetzbasierte Agenten. Diploma thesis, Universität Hamburg, Fachbereich Informatik, Vogt--Kölln Str. 30, D--22527 Hamburg, Dec. 2002.]]Google ScholarGoogle Scholar
  7. E. B. Fernandez and P. Morrison. Securing the Broker pattern. In Proceedings of the European Conference on Pattern Languages of Programs (EuroPLoP). Department of Computer Science & Engineering, Florida Atlantic University, USA, 2006.]]Google ScholarGoogle Scholar
  8. Foundation for Intelligent Physical Agents (FIPA) -- homepage. http://www.fipa.org/. Foundation for Intelligent Physical Agents.]]Google ScholarGoogle Scholar
  9. S. Fischmeister, G. Vigna, and R. A. Kemmerer. Evaluating the security of three Java--based mobile agent systems. In Mobile Agents: 5th International Conference, Atlanta, GA, USA. Proceedings, pages 31--41. Springer, 2001.]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  10. D. S. Frankel. Model Driven Architecture: Applying MDA to Enterprise Computing. Wiley, 2003.]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  11. A. Fuxman, M. Pistore, J. Mylopoulos, and P. Traverso. Model checking early requirements specifications in Tropos. In IEEE International Symposium on Requirements Engineering, 2001.]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  12. E. Gamma, R. Helm, R. Johnson, and J. Vlissides. Design Patterns: Elements of Reusable Object-Oriented Software. Addison-Wesley Longman Publishing Co., Inc. Boston, MA, USA, 1995.]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  13. M. Gasser. Building a secure computer system. Van Nostrand Reinhold Co., New York, NY, USA, 1988.]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  14. C. Girault and R. Valk. Petri Nets for Systems Engineering -- A Guide to Modeling, Verification, and Applications. Springer, 2003.]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  15. S. T. Halkidis, A. Chatzigeorgiou, and G. Stephanides. A qualitative evaluation of security patterns. In Sixth International Conference on Information and Communications Security (ICICS), LNCS, pages 132--144. Springer, Oct. 2004.]]Google ScholarGoogle ScholarCross RefCross Ref
  16. D. Hatebur, M. Heisel, and H. Schmidt. A security engineering process based on patterns. dexa, 0:734--738, 2007. SPattern'07.]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  17. V. Horvath. Security patterns for multi-agent systems: Review and implementation in mulan/capa. Diploma thesis, Universität Hamburg, Department Informatik, Vogt-Kölln Str. 30, D--22527 Hamburg, Dec. 2007.]]Google ScholarGoogle Scholar
  18. N. R. Jennings. On agent--based software engineering. Artificial Intelligence, 117(2):277--296, 2000.]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  19. J. Jürjens. Secure Systems Development with UML. Springer, 2004.]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  20. O. Kummer. Referenznetze. Logos Verlag, Berlin, 2002.]]Google ScholarGoogle Scholar
  21. O. Kummer, F. Wienberg, and M. Duvigneau. Renew -- the Reference Net Workshop. Available at: http://www.renew.de/, May 2006. Release 2.1.]]Google ScholarGoogle Scholar
  22. S. Lehtonen and J. Pärssinen. A pattern language for key management. In Eighth Conference on Pattern Languages of Programs (PLoP 2001), Allerton Park, Monticello, Illinois, USA, Sept. 2001.]]Google ScholarGoogle Scholar
  23. H. Mouratidis, M. Weiss, and P. Giorgini. Modeling secure systems using an agent--oriented approach and security patterns. International Journal of Software Engineering and Knowledge Engineering, 16(3):471, 2006.]]Google ScholarGoogle ScholarCross RefCross Ref
  24. M. Naedele and J. W. Janneck. Design patterns in petri net system modeling. In Proc. 4th IEEE Int. Conf. on Engineering of Complex Computer Systems, 10--14 August 1998, Monterey, CA, pages 47--54, Aug. 1998.]]Google ScholarGoogle ScholarCross RefCross Ref
  25. I. Porres and M. C. Valiente. Process definition and project tracking in model driven engineering. In J. Münch and M. Vierimaa, editors, PROFES, volume 4034 of LNCS, pages 127--141. Springer, 2006.]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  26. H. Reza and X. He. Pattern--based software architecture: A case study. In Proc. of the IEEE International Conference on Information Technology: Coding and Computing, Las Vegas, pages 592--597, May 2003.]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  27. P. Robinson. Extensible security patterns. dexa, 0:729--733, Sept. 2007. Workshop SPattern'07.]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  28. H. Rölke. Modellierung von Agenten und Multiagentensystemen -- Grundlagen und Anwendungen, volume 2 of Agent Technology -- Theory and Applications. Logos Verlag, Berlin, 2004.]]Google ScholarGoogle Scholar
  29. M. Schumacher. Security Engineering with Patterns -- Origins, Theoretical Models, and New Applications, volume 2754 of LNCS. Springer, 2003.]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  30. R. Valk. Petri nets as token objects -- an introduction to elementary object nets. In J. Desel and M. Silva, editors, 19th International Conference on Application and Theory of Petri nets, Lisbon, Portugal, number 1420 in LNCS, pages 1--25. Springer, 1998.]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  31. J. W. Yoder and J. Barcalow. Architectural patterns for enabling application security. In Fourth Conference on Pattern Languages of Programs (PLoP 1997), Allerton Park, Monticello, Illinois, USA, Sept. 1997.]]Google ScholarGoogle Scholar

Index Terms

  1. From security patterns to implementation using petri nets

          Recommendations

          Comments

          Login options

          Check if you have access through your login credentials or your institution to get full access on this article.

          Sign in
          • Published in

            cover image ACM Conferences
            SESS '08: Proceedings of the fourth international workshop on Software engineering for secure systems
            May 2008
            72 pages
            ISBN:9781605580425
            DOI:10.1145/1370905
            • Program Chairs:
            • Bart De Win,
            • Seok-Won Lee,
            • Mattia Monga

            Copyright © 2008 ACM

            Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

            Publisher

            Association for Computing Machinery

            New York, NY, United States

            Publication History

            • Published: 17 May 2008

            Permissions

            Request permissions about this article.

            Request Permissions

            Check for updates

            Qualifiers

            • research-article

            Acceptance Rates

            Overall Acceptance Rate8of11submissions,73%

            Upcoming Conference

            ICSE 2025

          PDF Format

          View or Download as a PDF file.

          PDF

          eReader

          View online with eReader.

          eReader