A Security Design Pattern Taxonomy based on Attack Patterns

Andreas Wiesauer, Johannes Sametinger

Research output: Chapter in Book/Report/Conference proceedingConference proceedingspeer-review

Abstract

Security design patterns are proven solutions to security problems in a given context with constructive measures of how to design certain parts of a software system. The literature contains numerous definitions, examples, and taxonomies of such patterns. There are also a few quality criteria for them. We suggest a new taxonomy based on attack patterns in order to enhance applicability of security design patterns especially for non-experts in software security. We further suggest a combined consideration of attack patterns, security design patterns and test cases for the validation and evaluation of security design Patterns.
Original languageEnglish
Title of host publicationInternational Joint Conference on e-Business and Telecommunications, Milan, Italy, July 7-10, 2009
Pages387-394
Number of pages7
Publication statusPublished - 2009

Fields of science

  • 102006 Computer supported cooperative work (CSCW)
  • 102015 Information systems
  • 102016 IT security
  • 102020 Medical informatics
  • 102022 Software development
  • 102027 Web engineering
  • 502032 Quality management
  • 502050 Business informatics
  • 503015 Subject didactics of technical sciences
  • 102034 Cyber-physical systems
  • 509026 Digitalisation research
  • 102040 Quantum computing 

Cite this