Evaluating fault tolerance in security requirements of web services.

It is impossible to identify all of the internal and external security faults (vulnerabilities and threats) during the security analysis of web services. Hence, complete fault prevention would be impossible and consequently a security failure may occur within the system. To avoid security failur...

Full description

Bibliographic Details
Main Authors: Mougouei, Davoud, Wan Ab. Rahman, Wan Nurhayati, Almasi, Mohammad Moein
Format: Conference or Workshop Item
Language:English
English
Published: 2012
Online Access:http://psasir.upm.edu.my/id/eprint/27700/
http://psasir.upm.edu.my/id/eprint/27700/1/ID%2027700.pdf
_version_ 1848845912887001088
author Mougouei, Davoud
Wan Ab. Rahman, Wan Nurhayati
Almasi, Mohammad Moein
author_facet Mougouei, Davoud
Wan Ab. Rahman, Wan Nurhayati
Almasi, Mohammad Moein
author_sort Mougouei, Davoud
building UPM Institutional Repository
collection Online Access
description It is impossible to identify all of the internal and external security faults (vulnerabilities and threats) during the security analysis of web services. Hence, complete fault prevention would be impossible and consequently a security failure may occur within the system. To avoid security failures, we need to provide a measurable level of fault tolerance in the security requirements of target web service. Although there are some approaches toward assessing the security of web services but still there is no well-defined evaluation model for security improvement specifically during the requirement engineering phase. This paper introduces a measurement model for evaluating the degree of fault tolerance (FTMM) in security requirements of web services by explicitly factoring the mitigation techniques into the evaluation process which eventually contributes to required level of fault tolerance in security requirements. Our approach evaluates overall tolerance of the target service in the presence of the security faults through evaluating the computational security requirement model (SRM) of the service. We measure fault tolerance of the target web service by taking into consideration the cost, technical ability, impact and flexibility of the security goals established to mitigate the security faults
first_indexed 2025-11-15T08:54:22Z
format Conference or Workshop Item
id upm-27700
institution Universiti Putra Malaysia
institution_category Local University
language English
English
last_indexed 2025-11-15T08:54:22Z
publishDate 2012
recordtype eprints
repository_type Digital Repository
spelling upm-277002014-06-19T06:35:03Z http://psasir.upm.edu.my/id/eprint/27700/ Evaluating fault tolerance in security requirements of web services. Mougouei, Davoud Wan Ab. Rahman, Wan Nurhayati Almasi, Mohammad Moein It is impossible to identify all of the internal and external security faults (vulnerabilities and threats) during the security analysis of web services. Hence, complete fault prevention would be impossible and consequently a security failure may occur within the system. To avoid security failures, we need to provide a measurable level of fault tolerance in the security requirements of target web service. Although there are some approaches toward assessing the security of web services but still there is no well-defined evaluation model for security improvement specifically during the requirement engineering phase. This paper introduces a measurement model for evaluating the degree of fault tolerance (FTMM) in security requirements of web services by explicitly factoring the mitigation techniques into the evaluation process which eventually contributes to required level of fault tolerance in security requirements. Our approach evaluates overall tolerance of the target service in the presence of the security faults through evaluating the computational security requirement model (SRM) of the service. We measure fault tolerance of the target web service by taking into consideration the cost, technical ability, impact and flexibility of the security goals established to mitigate the security faults 2012 Conference or Workshop Item NonPeerReviewed application/pdf en http://psasir.upm.edu.my/id/eprint/27700/1/ID%2027700.pdf Mougouei, Davoud and Wan Ab. Rahman, Wan Nurhayati and Almasi, Mohammad Moein (2012) Evaluating fault tolerance in security requirements of web services. In: The International Conference on Cyber Security, Cyber Warfare and Digital Forensic, 26-28 June 2012, Kuala Lumpur. (pp. 111-116). English
spellingShingle Mougouei, Davoud
Wan Ab. Rahman, Wan Nurhayati
Almasi, Mohammad Moein
Evaluating fault tolerance in security requirements of web services.
title Evaluating fault tolerance in security requirements of web services.
title_full Evaluating fault tolerance in security requirements of web services.
title_fullStr Evaluating fault tolerance in security requirements of web services.
title_full_unstemmed Evaluating fault tolerance in security requirements of web services.
title_short Evaluating fault tolerance in security requirements of web services.
title_sort evaluating fault tolerance in security requirements of web services.
url http://psasir.upm.edu.my/id/eprint/27700/
http://psasir.upm.edu.my/id/eprint/27700/1/ID%2027700.pdf