Invention Grant
US09565201B2 Security threat identification/testing using annotated sequence diagrams
有权
使用注释序列图进行安全威胁识别/测试
- Patent Title: Security threat identification/testing using annotated sequence diagrams
- Patent Title (中): 使用注释序列图进行安全威胁识别/测试
-
Application No.: US14667363Application Date: 2015-03-24
-
Publication No.: US09565201B2Publication Date: 2017-02-07
- Inventor: Luca Compagna , Serena Ponta
- Applicant: Luca Compagna , Serena Ponta
- Applicant Address: DE Walldorf
- Assignee: SAP SE
- Current Assignee: SAP SE
- Current Assignee Address: DE Walldorf
- Agency: Fountainhead Law Group P.C.
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/57

Abstract:
Embodiments provide apparatuses and methods supporting software development teams in identifying potential security threats, and then testing those threats against under-development scenarios. At design-time, embodiments identify potential threats by providing sequence diagrams enriched with security annotations. Security information captured by the annotations can relate to topics such as security goals, properties of communications channels, environmental parameters, and/or WHAT-IF conditions. The annotated sequence diagram can reference an extensible catalog of functions useful for defining message content. Once generated, the annotated sequence diagram can in turn serve as a basis for translation into a formal model of system security. At run-time, embodiments support development teams in testing, by exploiting identified threats to automatically generate and execute test-cases against the up and running scenario. The security annotations may facilitate detection of subtle flaws in security logic, e.g., those giving rise to Man-in-the-middle, authentication, and/or confidentiality issues in software under-development.
Public/Granted literature
- US20160285902A1 Security Threat Identification/Testing Using Annotated Sequence Diagrams Public/Granted day:2016-09-29
Information query