UPM Institutional Repository

Evaluating fault tolerance in security requirements of web services.


Citation

Mougouei, Davoud and Wan Ab. Rahman, Wan Nurhayati and Almasi, Mohammad Moein (2012) Evaluating fault tolerance in security requirements of web services. In: The International Conference on Cyber Security, Cyber Warfare and Digital Forensic, 26-28 June 2012, Kuala Lumpur. (pp. 111-116).

Abstract

It is impossible to identify all of the internal and external security faults (vulnerabilities and threats) during the security analysis of web services. Hence, complete fault prevention would be impossible and consequently a security failure may occur within the system. To avoid security failures, we need to provide a measurable level of fault tolerance in the security requirements of target web service. Although there are some approaches toward assessing the security of web services but still there is no well-defined evaluation model for security improvement specifically during the requirement engineering phase. This paper introduces a measurement model for evaluating the degree of fault tolerance (FTMM) in security requirements of web services by explicitly factoring the mitigation techniques into the evaluation process which eventually contributes to required level of fault tolerance in security requirements. Our approach evaluates overall tolerance of the target service in the presence of the security faults through evaluating the computational security requirement model (SRM) of the service. We measure fault tolerance of the target web service by taking into consideration the cost, technical ability, impact and flexibility of the security goals established to mitigate the security faults


Download File

[img] PDF
ID 27700.pdf - Published Version
Restricted to Repository staff only

Download (391kB)

Additional Metadata

Item Type: Conference or Workshop Item (Paper)
Divisions: Faculty of Computer Science and Information Technology
Notes: Full text are available at Special Collection Division Office.
Keywords: Web service; Threat; Security fault.
Depositing User: Erni Suraya Abdul Aziz
Date Deposited: 06 May 2014 06:21
Last Modified: 19 Jun 2014 06:35
URI: http://psasir.upm.edu.my/id/eprint/27700
Statistic Details: View Download Statistic

Actions (login required)

View Item View Item