• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

用于指定横切安全威胁及缓解措施的形式化面向方面误用案例。

Formalized aspect-oriented misuse case for specifying crosscutting security threats and mitigations.

作者信息

Iqbal Shumaila, Faiz Rizwan Bin, Usman Muhammad, Rehman Shafiq Ur

机构信息

Department of Computing, Riphah International University, Islamabad, Pakistan.

Department of Computer Science, Fazaia Bilquis College of Education, PAF Base Nur Khan, Air University, Rawalpindi, Pakistan.

出版信息

PLoS One. 2025 Sep 12;20(9):e0322664. doi: 10.1371/journal.pone.0322664. eCollection 2025.

DOI:10.1371/journal.pone.0322664
PMID:40938936
原文链接:https://pmc.ncbi.nlm.nih.gov/articles/PMC12431249/
Abstract

Software applications are essential for managing daily life activities, including social interactions and business transactions, that significantly increase the need for security in sharing sensitive information. Misuse case modeling is used for identifying and analyzing security requirements in software applications. However, security threats and their corresponding mitigations are inherently cross-cutting concerns. These concerns are scattered and tangled within multiple functional requirements and cannot be modularized using traditional object-oriented techniques. The realization of misuse cases causes crosscutting threats and corresponding mitigations to be scattered and tangled across use cases, resulting in ambiguity, incomplete understanding, and insufficient analysis of security requirements. This study proposes a misuse case modelling method called Aspect-oriented Formalized Misuse Case (AFMUC). It specifies crosscutting security threats separately as an aspect misuse case and integrates them with use cases using an aspect-oriented approach. AFMUC provides structured guidelines and restriction rules for modeling crosscutting security threats and corresponding mitigations using aspect-oriented constructs such as Pointcut, Joinpoint Advice, and Introduction. The aspect threat model is then woven into the base use case model. Similarly, an aspect mitigation model is proposed to specify crosscutting mitigations following the AFMUC restriction rules. The aspect mitigation model is then woven into the base misuse case model. The proposed approach is applied to a case study and evaluated through a controlled experiment involving twenty-four students with a background in information security. The findings indicate that the AFMUC approach is practical and unambiguous for specifying and analyzing crosscutting security requirements. However, some aspect-oriented modeling constructs and restriction rules have been misapplied by students. This shows that while students favored the AFMUC approach, they may have found it challenging to apply the aspect-oriented constructs and restriction rules due to a limited exposure to aspect-oriented modelling.

摘要

软件应用程序对于管理日常生活活动至关重要,这些活动包括社交互动和商业交易,这显著增加了共享敏感信息时对安全性的需求。误用案例建模用于识别和分析软件应用程序中的安全需求。然而,安全威胁及其相应的缓解措施本质上是横切关注点。这些关注点分散且交织在多个功能需求中,无法使用传统的面向对象技术进行模块化。误用案例的实现导致横切威胁和相应的缓解措施分散并交织在各个用例中,从而导致安全需求的模糊性、理解不完整和分析不足。本研究提出了一种名为面向方面形式化误用案例(AFMUC)的误用案例建模方法。它将横切安全威胁单独指定为一个方面误用案例,并使用面向方面的方法将它们与用例集成。AFMUC提供了结构化指南和限制规则,用于使用切入点、连接点通知和引入等面向方面的构造对横切安全威胁和相应的缓解措施进行建模。然后将方面威胁模型编织到基本用例模型中。同样,提出了一个方面缓解模型,以按照AFMUC限制规则指定横切缓解措施。然后将方面缓解模型编织到基本误用案例模型中。所提出的方法应用于一个案例研究,并通过一项涉及24名具有信息安全背景的学生的对照实验进行评估。研究结果表明,AFMUC方法在指定和分析横切安全需求方面是实用且明确的。然而,学生们误用了一些面向方面的建模构造和限制规则。这表明,虽然学生们喜欢AFMUC方法,但由于对面向方面建模的接触有限,他们可能发现应用面向方面的构造和限制规则具有挑战性。

相似文献

1
Formalized aspect-oriented misuse case for specifying crosscutting security threats and mitigations.用于指定横切安全威胁及缓解措施的形式化面向方面误用案例。
PLoS One. 2025 Sep 12;20(9):e0322664. doi: 10.1371/journal.pone.0322664. eCollection 2025.
2
Prescription of Controlled Substances: Benefits and Risks管制药品的处方:益处与风险
3
Short-Term Memory Impairment短期记忆障碍
4
Management of urinary stones by experts in stone disease (ESD 2025).结石病专家对尿路结石的管理(2025年结石病专家共识)
Arch Ital Urol Androl. 2025 Jun 30;97(2):14085. doi: 10.4081/aiua.2025.14085.
5
Aspects of Genetic Diversity, Host Specificity and Public Health Significance of Single-Celled Intestinal Parasites Commonly Observed in Humans and Mostly Referred to as 'Non-Pathogenic'.人类常见且大多被称为“非致病性”的单细胞肠道寄生虫的遗传多样性、宿主特异性及公共卫生意义
APMIS. 2025 Sep;133(9):e70036. doi: 10.1111/apm.70036.
6
Sexual Harassment and Prevention Training性骚扰与预防培训
7
Patient Restraint and Seclusion患者约束与隔离
8
Healthcare workers' informal uses of mobile phones and other mobile devices to support their work: a qualitative evidence synthesis.医护人员非正规使用手机和其他移动设备来支持工作:定性证据综合评价。
Cochrane Database Syst Rev. 2024 Aug 27;8(8):CD015705. doi: 10.1002/14651858.CD015705.pub2.
9
Interventions to reduce harm from continued tobacco use.减少持续吸烟危害的干预措施。
Cochrane Database Syst Rev. 2016 Oct 13;10(10):CD005231. doi: 10.1002/14651858.CD005231.pub3.
10
The Black Book of Psychotropic Dosing and Monitoring.《精神药物剂量与监测黑皮书》
Psychopharmacol Bull. 2024 Jul 8;54(3):8-59.

本文引用的文献

1
Modeling and verification of authentication threats mitigation in aspect-oriented mal sequence woven model.面向方面的恶意序列编织模型中的认证威胁缓解的建模与验证。
PLoS One. 2022 Jul 6;17(7):e0270702. doi: 10.1371/journal.pone.0270702. eCollection 2022.