Ar Arch chitectu tural An Analysi sis f s for
- r
Security ( y (AAF AAFS) S)
Jungwoo Ryoo and Priya Anand, Penn State University Rick Kazman, SEI/University of Hawaii
To appear in IEEE Security and Privacy
Ar Arch chitectu tural An Analysi sis f s for or Security ( - - PowerPoint PPT Presentation
Ar Arch chitectu tural An Analysi sis f s for or Security ( y (AAF AAFS) S) Jungwoo Ryoo and Priya Anand, Penn State University Rick Kazman, SEI/University of Hawaii To appear in IEEE Security and Privacy Arch chitectu ctural al
Jungwoo Ryoo and Priya Anand, Penn State University Rick Kazman, SEI/University of Hawaii
To appear in IEEE Security and Privacy
2
3
4
5
6
Security Tactics
Resist Attacks Encrypt Data Attack System detects, resists, reacts,
Detect Attacks Maintain Audit Trail Limit Exposure Recover from Attacks React to Attacks Revoke Access Lock Computer Detect Intrustion Detect Service Denial Verify Message Integrity Detect Message Delay Change Default Settings Separate Entities Restore See Availability Identify Actors Authenticate Actors Authorize Actors Limit Access Inform Actors
7
8
9
10
ToAA and PoAA
source code VoAA
11
ToAA PoAA VoAA
12
13
14
According to validation rules
Depending on the validation results
15
command
16
Standard library functions for sanitizing user inputs
17
96 65 12 61 SQL INJECTION XSS
OpenEMR Scan Results
3.1.0 4.1.2 18
19
20