Sciweavers

RE
2009
Springer

Trust Trade-off Analysis for Security Requirements Engineering

14 years 6 months ago
Trust Trade-off Analysis for Security Requirements Engineering
Abstract—Security requirements often have implicit assumptions about trust relationships among actors. The more actors trust each other, the less stringent the security requirements are likely to be. Trust always involves the risk of mistrust; hence, trust implies a trade-off: gaining some bene ts from depending on a second party in trade for getting exposed to security and privacy risks. When trust assumptions are implicit, these trust trade-offs are made implicitly and in an ad-hoc way. By taking advantage of agent- and goal-oriented analysis, we propose a method for discovering trade-offs that trust relationships bring. This method aims to help the analyst select among alternative dependency relationships by making explicit trust trade-offs. We propose a simple algorithm for making the trade-offs in a way that reaches a balance between costs and bene ts.
Golnaz Elahi, Eric S. K. Yu
Added 27 May 2010
Updated 27 May 2010
Type Conference
Year 2009
Where RE
Authors Golnaz Elahi, Eric S. K. Yu
Comments (0)