Model-based Confidentiality Analysis under Uncertainty
The result's identifiers
Result code in IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F00216208%3A11320%2F23%3A10474032" target="_blank" >RIV/00216208:11320/23:10474032 - isvavai.cz</a>
Result on the web
<a href="https://doi.org/10.1109/ICSA-C57050.2023.00062" target="_blank" >https://doi.org/10.1109/ICSA-C57050.2023.00062</a>
DOI - Digital Object Identifier
<a href="http://dx.doi.org/10.1109/ICSA-C57050.2023.00062" target="_blank" >10.1109/ICSA-C57050.2023.00062</a>
Alternative languages
Result language
angličtina
Original language name
Model-based Confidentiality Analysis under Uncertainty
Original language description
In our connected world, ensuring the confidentiality of the software systems we build becomes increasingly difficult. Model-based design time confidentiality analyses have been proposed to cope with this complexity early. However, the usefulness of such analyses is limited due to uncertainty about the software architecture itself and the software's execution environment. This leads to conclusions about confidentiality violations that lack both precision and comprehensiveness. Although there exist approaches to deal with design time uncertainty, existing research lacks precise statements about the impact of uncertainty on confidentiality. To address this, we include uncertainty as part of our software architectural model. We extend a data flow-based analysis to include the impact of uncertainty on confidentiality violations. The results of the case study-based evaluation show high accuracy with typical design time uncertainty. Also, our analysis yields more precise statements about the impact of uncertainty on confidentiality than the state of the art.
Czech name
—
Czech description
—
Classification
Type
D - Article in proceedings
CEP classification
—
OECD FORD branch
10201 - Computer sciences, information science, bioinformathics (hardware development to be 2.2, social aspect to be 5.8)
Result continuities
Project
<a href="/en/project/GC20-24814J" target="_blank" >GC20-24814J: FluidTrust – Enabling trust by fluid access control to data and physical resources in Industry 4.0 systems</a><br>
Continuities
P - Projekt vyzkumu a vyvoje financovany z verejnych zdroju (s odkazem do CEP)
Others
Publication year
2023
Confidentiality
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Data specific for result type
Article name in the collection
2023 IEEE 20TH INTERNATIONAL CONFERENCE ON SOFTWARE ARCHITECTURE COMPANION, ICSA-C
ISBN
978-1-66546-459-8
ISSN
2768-427X
e-ISSN
—
Number of pages
8
Pages from-to
256-263
Publisher name
IEEE COMPUTER SOC
Place of publication
LOS ALAMITOS
Event location
Aquila
Event date
Mar 13, 2023
Type of event by nationality
WRD - Celosvětová akce
UT code for WoS article
000990534100046