<?xml version="1.0" encoding="UTF-8"?>
<OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/ http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd">
  <responseDate>2026-07-20T10:41:56Z</responseDate>
  <request identifier="859" metadataPrefix="oai_dc" verb="GetRecord">https://drops.dagstuhl.de/oai</request>
  <GetRecord>
    <record>
      <header>
        <identifier>oai:drops-oai.dagstuhl.de:859</identifier>
        <datestamp>2024-03-06T11:07:03Z</datestamp>
        <setSpec>ddc:004</setSpec>
        <setSpec>open_access</setSpec>
      </header>
      <metadata>
        <oai_dc:dc xmlns:oai_dc="http://www.openarchives.org/OAI/2.0/oai_dc/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/oai_dc/ http://www.openarchives.org/OAI/2.0/oai_dc.xsd">
          <dc:title>A Framework for Analyzing Composition of Security Aspects</dc:title>
          <dc:creator>Fox, Jorge</dc:creator>
          <dc:creator>Juerjens, Jan</dc:creator>
          <dc:subject>Aspects in software engineering</dc:subject>
          <dc:subject>aspect interference</dc:subject>
          <dc:subject>verification</dc:subject>
          <dc:subject>semantics</dc:subject>
          <dc:subject>formal methods</dc:subject>
          <dc:description>The methodology of aspect-oriented software engineering has&#13;
been proposed to factor out concerns that are orthogonal to the core&#13;
functionality of a system. In particular, this is a useful approach to handling&#13;
the difficulties of integrating non-functional requirements such as&#13;
security into complex software systems. Doing so correctly and securely,&#13;
however, still remains a non-trivial task. For example, one has to make&#13;
sure that the "weaving" process actually enforces the aspects needed.&#13;
This is highly non-obvious especially in the case of security, since different&#13;
security aspects may actually contradict each other, in which case&#13;
they cannot be woven in a sequential way without destroying each other.&#13;
To address these problems, this paper introduces a framework for the&#13;
aspect-oriented development of secure software using composition filters&#13;
at the model level. Using an underlying foundation based on streamprocessing&#13;
functions, we explore under which conditions security properties&#13;
are preserved when composed as filters. Thanks to this foundation&#13;
we may also rely on model level verification tools and on code and model&#13;
weaving to remedy security failures. Our approach is explained using as&#13;
case-studies a web banking application developed by a major German&#13;
bank and a webstore design.</dc:description>
          <dc:publisher>Schloss Dagstuhl – Leibniz-Zentrum für Informatik</dc:publisher>
          <dc:contributor>Jorge Fox and Jan Juerjens</dc:contributor>
          <dc:date>2007</dc:date>
          <dc:relation>Is Part Of Dagstuhl Seminar Proceedings, Volume 6351, Methods for Modelling Software Systems (MMOSS) (2007)</dc:relation>
          <dc:type>InProceedings</dc:type>
          <dc:type>Text</dc:type>
          <dc:type>doc-type:ResearchArticle</dc:type>
          <dc:type>publishedVersion</dc:type>
          <dc:format>application/pdf</dc:format>
          <dc:identifier>doi:10.4230/DagSemProc.06351.3</dc:identifier>
          <dc:identifier>urn:nbn:de:0030-drops-8594</dc:identifier>
          <dc:identifier>https://drops.dagstuhl.de/entities/document/10.4230/DagSemProc.06351.3</dc:identifier>
          <dc:language>eng</dc:language>
          <dc:rights>https://creativecommons.org/licenses/by/4.0/legalcode</dc:rights>
        </oai_dc:dc>
      </metadata>
    </record>
  </GetRecord>
</OAI-PMH>
