Secure Systems Development with UML

Chapter 6: Tool Support for UMLsec

For the ideas that were presented in the previous chapters to be of benefit in practice, it is important to have advanced tool support to assist in using them. In this chapter, we present the necessary background and some results achieved so far toward developing tool support for UMLsec. The developed tools can be used to check the constraints associated with UMLsec stereotypes mechanically, based on XMI output of the diagrams from the UML drawing tool in use. We also explain a framework for implementing verification routines for the constraints associated with the UMLsec stereotypes. The goal is that advanced users of the UMLsec approach should be able to use this framework to implement verification routines for the constraints of self-defined stereotypes.

Furthermore, we present research on linking the UMLsec approach with the automated analysis of security-critical data arising at runtime. Specifically, we present research on the construction of a tool which automatically checks the SAP R/3 configuration for security policy rules formulated as UML specifications. Because of its modular architecture and its standardized interfaces, the tool can be adapted to check security constraints in other kinds of application software, such as firewalls or other access control configurations.

Finally, we present some approaches for linking UML models to implementations. The aim is to ensure that the benefits gained from the model-based approach on the level of the system model actually carry over to the implemented system, as one would hope.

6.1 Extending UML CASE Tools with Analysis Tools

We present...

UNLIMITED FREE
ACCESS
TO THE WORLD'S BEST IDEAS

SUBMIT
Already a GlobalSpec user? Log in.

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.

Customize Your GlobalSpec Experience

Category: Integrated Development Environment (IDE)
Finish!
Privacy Policy

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.