This blog is concerned with Information Security and Business process management, and the integration of Security with BPM.
Tuesday, 27 April 2010
Research Methodology: Design Science
Design Science consist of 7 guidelines:
1- Addresses design as an artifact: must produce a viable artifact in the form of a construct, a model, a method, or an instantiation.
2- Describes problem relevance: where the objective of the research is to develop technology-based solutions to important and relevant business problems.
3- Describes the importance of using strict evaluation methods for the design: The utility, quality, and efficacy of a design artifact must be rigorously demonstrated via well-executed evaluation methods.
4- Addresses the importance of the work being considered as a contribution to the academic world: IS research effort should be considered a contribution to the field.
5- Focuses on research strictness: research relies upon the application of strict methods in both the construction and evaluation of the design artifact.
6- Design as a search process: the search for an effective artifact requires utilizing available means to reach desired ends while satisfying laws in the problem environment.
7- addresses the importance that the work be published: in both the academic community and in the practitioner’s community.
-----------------------------------------
Source:
DESIGN SCIENCE IN INFORMATION SYSTEMS RESEARCH.
Alan R. Hevner, Sudha Ram, Salvatore T. March, Jinsoo Park.
2004.
Monday, 26 April 2010
Confidentiality & BPM
Confidentiality is one of the three core security goals.
Security has always defined confidentiality, integrity, and availability to be
the core principles of information security, these three, also know as the “CIA
triad”, are the hard security requirements (Allen,
2001).
Confidentiality
was defined by the International Organization for Standardization (ISO) in
ISO-17799 as "ensuring that information is accessible only to those
authorized to have access". So basically confidentiality is to make sure
that unauthorized personal will not get access to the information, and that can
be easily reflect on BPM and need for it in BPM can be seen.
Vijay Atluri (2002)
defines confidentiality in BPM terms when he says: “This refers to unauthorized
disclosure of information including the workflow specification, and the
workflow instances during its execution”.
Alhaqbani et al. (2010) in terms of distinguishing between privacy and
confidentiality they say that data confidentiality aim to give the owner of the
data control over its accessibility.
An example to show the
importance on confidentiality in BPM lets take an example of an “Payment”
process in an on line parches. For the example let us assume that Adam wants to
buy something from company’s “A” website. One important part of the parches
process is the payment process, where the website offers the use of credit
card, during this process Adam has the right to ask for his credit card
information to e hidden and that non of the employees working in this company
can see it; while this process can not be completed without Adam providing such
information. So this is a case here information needed to be entered to the
process while also the owner of the information requires a confidentiality restriction
on this information. This is a case shows how important it is to have
confidentiality control in BPM.
Currently there are not
any specific solution that was proposed to as a solution to the confidentiality
problem in BPM, but the work done by Alhaqbani et al. (2010), which was a
solution for the privacy, is an outstanding solution and also can be used to
solve the confidentiality requirement, there solution can be easily modified to
be used also as a confidentiality solution.
-------------------------------
All Rights reserved @ Khalid Alissa 2010.
Thursday, 22 April 2010
Formal representation of security requirements in workflow domain
A paper written by Basit Shafiq, Arjmand Samuel, Elisa Bertino, and Arif Ghafoor. Called "A Technique for Optimal Adaptation of Time-Dependent Workflows with Security Constraints".
This paper gave a nice representation of security requirements in a mathematical formulas.
They maged to represent: Time, Role, User, Task, Constrains, and the delay. They had it all in what they called "mixed-integer programming"
For example, if we have a task that we need to be only processed during a specific time, and we have a security "Time constraint" where the task should be only performed during specific time for a certain role: (t1, [dmin, dmax], enable τ) as
t1: is the object.
dmin: starting time.
dmax: end time.
τ: is the task.
The Security constraint can be represented as: tsτ = t1, tfτ - tsτ≥dmin iτ, and tfτ - tsτ≤dmax iτ.
this might seem a little difficult to understand, but believe me this security constraint was the easiest to represent.
let take it one by one to explaine the privouce formaula as it easy as you will see.
the formula says: Task performer of the task "τ" will be object "t1" only and only if "task finish time - task start time is larger than the starting time for this task", and "task finish time - task start time is less than the ending time for this task".
the paper include other intersting security requirments represented in mathematical formal equations.
This paper gave a nice representation of security requirements in a mathematical formulas.
They maged to represent: Time, Role, User, Task, Constrains, and the delay. They had it all in what they called "mixed-integer programming"
For example, if we have a task that we need to be only processed during a specific time, and we have a security "Time constraint" where the task should be only performed during specific time for a certain role: (t1, [dmin, dmax], enable τ) as
t1: is the object.
dmin: starting time.
dmax: end time.
τ: is the task.
The Security constraint can be represented as: tsτ = t1, tfτ - tsτ≥dmin iτ, and tfτ - tsτ≤dmax iτ.
this might seem a little difficult to understand, but believe me this security constraint was the easiest to represent.
let take it one by one to explaine the privouce formaula as it easy as you will see.
the formula says: Task performer of the task "τ" will be object "t1" only and only if "task finish time - task start time is larger than the starting time for this task", and "task finish time - task start time is less than the ending time for this task".
the paper include other intersting security requirments represented in mathematical formal equations.
Privacy-aware Workflow management .. what a nice paper.
A summery of this paper is posted in the blog (under the "Work done" section). but in general i like the idea they proposed of how to solve the problem of privacy, and i believe that the same idea can be used to solve other security requirements such as integrity.
The idea was based on 4 main points: adding the subject, Auxiliary data, work allocation, and data patterns.
but it all comes to what is represented in this diagram:
As it is clear (without going in to details) that every subject has it is own sittings and authorization requirements, so before processing any subject through the workflow, the system will make sure that the privacy requirements are satisfied.
i personally believe that the same idea can be used to satisfy other security requirements such as "integrity"; for example we can add a field in the records to show the owner of the subject, and then another field show last modification, and by whom it was done.
so even if a person is allowed to see the subject information (satisfying privacy requirement) he might not be allowed to modify the information.
this idea will be explored more in the future.
PhD comics
while i was surfing the internet i found this cool site called "www.phdcomics.com" i really liked there comics .. they are really good.
this is a one i liked:
you can read more comics on there website www.phdcomics.com.
this is a one i liked:
you can read more comics on there website www.phdcomics.com.
Tuesday, 20 April 2010
Subscribe to:
Posts (Atom)


