{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T16:28:05Z","timestamp":1781108885853,"version":"3.54.1"},"reference-count":29,"publisher":"IGI Global Scientific Publishing","issue":"3","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2013,7]]},"abstract":"<jats:p>The authors cannot comprehensively determine all of the vulnerabilities to an attack only from requirements descriptions. To resolve the problem, the authors propose a method for eliciting security requirements using the information about system architecture. The authors convert a use-case description into a variation of a data flow diagram called an asset-flow diagram (AFD). The authors then refine the AFDs based on a processor deployment diagram (PDD), which gives information about a system architecture. By using vulnerabilities patterns to an attack, the authors distinguish vulnerabilities to the attack that can be identifiable in AFDs from remaining vulnerabilities to the attack. To prohibit the former vulnerabilities, security requirements are defined as countermeasures and\/or modification of existing requirements. To prevent the latter vulnerabilities, security requirements are defined as design and implementation constraints. Through an evaluation of a web application, the authors show that our method enables us to elicit security requirements against several different attacks in different system architectures.<\/jats:p>","DOI":"10.4018\/jsse.2013070103","type":"journal-article","created":{"date-parts":[[2013,9,3]],"date-time":"2013-09-03T12:54:26Z","timestamp":1378212866000},"page":"42-63","source":"Crossref","is-referenced-by-count":2,"title":["Eliciting Security Requirements for an Information System using Asset Flows and Processor Deployment"],"prefix":"10.4018","volume":"4","author":[{"given":"Haruhiko","family":"Kaiya","sequence":"first","affiliation":[{"name":"Department of Computer Science, Shinshu University, Nagano, Japan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Junya","family":"Sakai","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Shinshu University, Nagano, Japan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shinpei","family":"Ogata","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Shinshu University, Nagano, Japan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kenji","family":"Kaijiri","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Shinshu University, Nagano, Japan"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"jsse.2013070103-0","unstructured":"Bishop, M. (2003). Computer security: Art and science. Addison-Wesley, Pearson Education, Inc."},{"key":"jsse.2013070103-1","doi-asserted-by":"crossref","unstructured":"Br\u00e6ndeland, G., & St\u00f8len, K. (2006). Using model-based security analysis in component-oriented system development. In Proceedings of the Quality of Protection (QoP) (p. 11-18). ACM","DOI":"10.1145\/1179494.1179498"},{"key":"jsse.2013070103-2","unstructured":"Chunlei, W., Gang, Z., & Yiqi, D. (2009). An efficient control flow security analysis approach for binary executables. In Proceedings of the IEEE International Conference on Computer Science and Information Technology (p. 272-276). IEEE."},{"key":"jsse.2013070103-3","author":"T.DeMarco","year":"1979","journal-title":"Structured analysis and system specification"},{"key":"jsse.2013070103-4","doi-asserted-by":"crossref","unstructured":"Giorgini, P., Massacci, F., Mylopoulos, J., & Zannone, N. (2005). Modeling security requirements through ownership, permission and delegation. In Proceedings of the IEEE International Conference on Requirements Engineering (RE\u201905) (p. 167-176). IEEE CPS.","DOI":"10.1109\/RE.2005.43"},{"key":"jsse.2013070103-5","author":"D.Gollmann","year":"1999","journal-title":"Computer security"},{"key":"jsse.2013070103-6","doi-asserted-by":"crossref","unstructured":"Heyman, T., Yskout, K., Scandariato, R., Schmidt, H., & Yu, Y. (2011). The security twin peaks. In Proceedings of the International Conference on Engineering Secure Software and Systems (ESSoS) (p. 167-180). Springer.","DOI":"10.1007\/978-3-642-19125-1_13"},{"key":"jsse.2013070103-7","first-page":"1172","article-title":"Covering your assets in software engineering","author":"M. G.Jaatun","year":"2008","journal-title":"Availability, Reliability and Security (ARES)"},{"key":"jsse.2013070103-8","author":"M.Jackson","year":"2000","journal-title":"Problem frames, analyzing and structuring software development problems"},{"key":"jsse.2013070103-9","doi-asserted-by":"crossref","unstructured":"Jin-Liang, X., Xiao-Hong, L., Yan, C., Zhi-Yong, F., & Ran, L. (2010). Information flow analysis of web service net. In Proceedings of the IEEE International Conference on Computer and Information Technology (pp. 1622-1626). IEEE.","DOI":"10.1109\/CIT.2010.287"},{"key":"jsse.2013070103-10","doi-asserted-by":"crossref","unstructured":"Liu, L., Yu, E. S. K., & Mylopoulos, J. (2003). Security and privacy requirements analysis within a social setting. In Proceedings of the International Conference on Requirements Engineering (RE) (p. 151-161). IEEE.","DOI":"10.1109\/ICRE.2003.1232746"},{"key":"jsse.2013070103-11","doi-asserted-by":"crossref","unstructured":"Long, T., Liu, L., Yu, Y., & Jin, Z. (2009). Avt vector: A quantitative security requirements evaluation approach based on assets, vulnerabilities and trustworthiness of environment. In Proceedings of the International Conference on Requirements Engineering (RE) (p. 377-378). IEEE.","DOI":"10.1109\/RE.2009.53"},{"key":"jsse.2013070103-12","unstructured":"Marino, B. D. R., Haddad, H. M., & A., J. E. M. (2009). A methodological tool for asset identification in web applications: Security risk assessment. In Proceedings of the International Conference on Software Engineering Advances (ICSEA) (p. 413-418). IEEE."},{"key":"jsse.2013070103-13","unstructured":"Marino, B. D. R., & Haddad, H. M. (2010). Asset assessment in web applications. In Proceedings of the Information Technology: New Generations (ITNG) (p. 762-767). IEEE."},{"key":"jsse.2013070103-14","first-page":"3137","article-title":"Analyzing impacts on software enhancement caused by security design alternatives with patterns.","author":"T.Okubo","year":"2012","journal-title":"International Journal of Secure Software Engineering"},{"key":"jsse.2013070103-15","doi-asserted-by":"crossref","unstructured":"Okubo, T., Taguchi, K., & Yoshioka, N. (2009). Misuse cases + assets + security goals. In Proceedings of the International Conference on Computational Science and Engineering (CSE) (Vol. 3, pp. 424-429). IEEE.","DOI":"10.1109\/CSE.2009.18"},{"key":"jsse.2013070103-16","unstructured":"OWASP. (2010). OWASP: The open web application security project. Retrieved from https:\/\/www.owasp.org\/index.php\/Category:OWASP_Top_Ten_Project"},{"key":"jsse.2013070103-17","unstructured":"Rosenberg, D., & Stephens, M. (2007). Use case driven object modeling with UML, theory and practice. apress."},{"key":"jsse.2013070103-18","doi-asserted-by":"crossref","unstructured":"Russo, A., & Sabelfeld, A. (2010). Dynamic vs. static flow-sensitive security analysis, In Proceedings of the Computer Security Foundations Symposium (p. 186-199). IEEE.","DOI":"10.1109\/CSF.2010.20"},{"key":"jsse.2013070103-19","doi-asserted-by":"crossref","unstructured":"Seeger, M. M. (2011). Using control-flow techniques in a security context: A survey on common prototypes and their common weakness. In Proceedings of the International Conference on Network Computing and Information Security (p. 133-137). IEEE.","DOI":"10.1109\/NCIS.2011.126"},{"key":"jsse.2013070103-20","doi-asserted-by":"publisher","DOI":"10.1007\/s00766-004-0194-4"},{"key":"jsse.2013070103-21","author":"I. E. E. E.Standard","year":"1998","journal-title":"IEEE recommended practice for software requirements specifications. IEEE Std. 830-1998"},{"key":"jsse.2013070103-22","unstructured":"ISO Standard. (2004). ISO\/IEC 13335-1:2004 Information technology - Security techniques. Management of information and communications technology security."},{"key":"jsse.2013070103-23","unstructured":"ISO Standard. (2005). ISO\/IEC 27002 Information technology - Security techniques. Code of practice for information security management."},{"key":"jsse.2013070103-24","doi-asserted-by":"crossref","unstructured":"Supaporn, K., Prompoon, N., & Rojkangsadan, T. (2007). Enterprise assets security requirements construction from esrmg grammar based on security patterns. In Proceedings of the Asia-Pacific Software Engineering Conference (APSEC) (p. 112-119). IEEE CPS.","DOI":"10.1109\/ASPEC.2007.53"},{"key":"jsse.2013070103-25","author":"F.Swiderski","year":"2004","journal-title":"Threat modeling"},{"key":"jsse.2013070103-26","doi-asserted-by":"crossref","unstructured":"van Lamsweerde, A. (2004). Elaborating security requirements by construction of intentional anti-models. In Proceedings of the International Conference on Software Engineering (ICSE) (p. 148-157). IEEE.","DOI":"10.1109\/ICSE.2004.1317437"},{"key":"jsse.2013070103-27","doi-asserted-by":"publisher","DOI":"10.1145\/237432.237434"},{"key":"jsse.2013070103-28","doi-asserted-by":"crossref","unstructured":"Zhao, G., Chen, H., & Wang, D. (2008). Data-flow based analysis of Java Bytecode vulnerability. In Proceedings of the International Conference on Web-Age Information Management (p. 647-653). IEEE.","DOI":"10.1109\/WAIM.2008.99"}],"container-title":["International Journal of Secure Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=83634","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,7,22]],"date-time":"2019-07-22T23:44:41Z","timestamp":1563839081000},"score":1,"resource":{"primary":{"URL":"http:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/jsse.2013070103"}},"subtitle":[""],"short-title":[],"issued":{"date-parts":[[2013,7]]},"references-count":29,"journal-issue":{"issue":"3"},"URL":"https:\/\/doi.org\/10.4018\/jsse.2013070103","relation":{},"ISSN":["1947-3036","1947-3044"],"issn-type":[{"value":"1947-3036","type":"print"},{"value":"1947-3044","type":"electronic"}],"subject":[],"published":{"date-parts":[[2013,7]]}}}