Web services composition allows a software designer for combining atomic services, for instance taken from a marketplace, in a complex business process fullling a desired functional goal. Moreover, among a large number of possible compositions, the designer may want to consider only those which satisfy specic non-functional requirements. In our work we consider verication of security properties and evaluation quantitative security metrics in a single framework. The main focus of this article is the verication of a composition with several security metrics at once. We provide a general solution for the problem and show how such verication can be made more ecient in specic cases (e.g., when a metric is an abstraction of another one). We employ a mathematical structure called c-semirings granting the generality of our approach.

Multi-dimensional Secure Service Orchestration

Fabio Martinelli;Artsiom Yautsiukhin
2013

Abstract

Web services composition allows a software designer for combining atomic services, for instance taken from a marketplace, in a complex business process fullling a desired functional goal. Moreover, among a large number of possible compositions, the designer may want to consider only those which satisfy specic non-functional requirements. In our work we consider verication of security properties and evaluation quantitative security metrics in a single framework. The main focus of this article is the verication of a composition with several security metrics at once. We provide a general solution for the problem and show how such verication can be made more ecient in specic cases (e.g., when a metric is an abstraction of another one). We employ a mathematical structure called c-semirings granting the generality of our approach.
2013
Istituto di informatica e telematica - IIT
Inglese
2nd Workshop on Security in Business Process
Sì, ma tipo non specificato
Beijin
Business process
c-semirings
Security
security metrics
3
none
Costa, Gabriele; Martinelli, Fabio; Yautsiukhin, Artsiom
273
info:eu-repo/semantics/conferenceObject
04 Contributo in convegno::04.01 Contributo in Atti di convegno
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.14243/247509
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
social impact