Authors:
Pascal Bou Nassar
1
;
Youakim Badr
2
;
Frédérique Biennier
2
and
Kablan Barbar
3
Affiliations:
1
Agence Universitaire de la Francophonie, Lebanon
;
2
Université de Lyon, France
;
3
Lebanese University, Lebanon
Keyword(s):
Security Management, Risk Management, Service-Oriented Architecture, Reference Models and Design Method.
Related
Ontology
Subjects/Areas/Topics:
Cloud Computing
;
Collaboration and e-Services
;
Communication and Software Technologies and Architectures
;
Computer-Supported Education
;
Data Engineering
;
e-Business
;
Energy and Economy
;
Enterprise Engineering
;
Enterprise Information Systems
;
Information Technologies Supporting Learning
;
Mobile and Pervasive Computing
;
Mobile Software and Services
;
Ontologies and the Semantic Web
;
Security and Privacy
;
Services Science
;
Software Agents and Internet Computing
;
Software Engineering
;
Software Engineering Methods and Techniques
;
Sustainable Computing and Communications
;
Telecommunications
;
Web Services
;
Wireless Information Networks and Systems
Abstract:
Many information security approaches deal with service-oriented architectures by focusing on security policies, requirements and technical implementation during service design, specification and implementation phases. Nevertheless, service-oriented architectures are increasingly deployed in open, distributed and dynamic environments, which particularly require an end-to-end security at each phase of the service’s lifecycle. Moreover, the security should not only focus on services without considering the risks and threats that might be caused by elements from business activities or underlying hardware and software infrastructure. In this paper, we develop a model highlighting the dependency between elements at business, service and infrastructure levels, defining the design context. In addition, we develop a holistic approach to define a security conceptual model, including services, security risks and security policies and guides all phases in a typical design method for service-orie
nted architectures.
(More)