Modern enterprise systems need to implement and comply to increasingly
complex security, compliance, and privacy policies. To address this need,
we developed SecureBPMN, a model-driven security approach for
process-driven systems.
SecureBPMN: model-driven security for process-driven systems §
SecureBPMN is a model-driven security approach for
business-process-driven systems. SecureBPMN integrates security and
privacy aspects into BPMN. It allows modeling, formally analyze SecureBPMN
models as well as to generate code and configuration artifacts.
The SecureBPMN Modeling and Verification Environment
On the one hand, SecureBPMN provides a domain-specific modeling language that
allows to model security aspects (e.g., access control, separation of
duty, confidentiality). SecurePBPMN is defined as a metamodel that
can easily be integrated into BPMN and, thus, can be used for modeling
secure and business processes as well as secure service compositions.
On the other hand, SecureBPMN provides and end-to-end modeling,
verification, and validation approach for building systems that comply
to complex security, privacy, or compliance requirements. The
SecureBPMN tool chain does not only support modeling of secure
business process and service compositions: it also supports the formal
analysis both on the level of SecureBPMN models and refinement
properties between the model and the actual implementation.
The SecureBPMN tool chain is free software: its source code is available
in our git repository.
M. Kohler, A. D. Brucker, and A. Schaad, “ProActiveCaching: Generating caching heuristics for business process environments,” in International conference on computational science and engineering (CSE), vol. 3, Los Alamitos, CA, USA: IEEE Computer Society, 2009, pp. 207–304. doi: 10.1109/CSE.2009.177. Author copy: http://logicalhacking.com/publications/kohler.ea-proactive-2009/
A. D. Brucker, F. Malmignati, M. Merabti, Q. Shi, and B. Zhou, “A framework for secure service composition,” in International conference on information privacy, security, risk and trust (PASSAT), Los Alamitos, CA, USA: IEEE Computer Society, 2013, pp. 647–652. doi: 10.1109/SocialCom.2013.97. Author copy: http://logicalhacking.com/publications/brucker.ea-framework-2013/
A. D. Brucker, F. Malmignati, M. Merabti, Q. Shi, and B. Zhou, “Aniketos service composition framework: Analysing and ranking of secure services,” in Secure and trustworthy service composition: The aniketos approach, A. D. Brucker, F. Dalpiaz, P. Giorgini, P. H. Meland, and E. Rios, Eds. Heidelberg: Springer-Verlag, 2014, pp. 121–135. doi: 10.1007/978-3-319-13518-2_9. Author copy: http://logicalhacking.com/publications/brucker.ea-aniketos-scf-2014/
[12]
A. D. Brucker, L. Compagna, and P. Guilleminot, “Compliance validation of secure service compositions,” in Secure and trustworthy service composition: The aniketos approach, A. D. Brucker, F. Dalpiaz, P. Giorgini, P. H. Meland, and E. Rios, Eds. Heidelberg: Springer-Verlag, 2014, pp. 136–149. doi: 10.1007/978-3-319-13518-2_10. Author copy: http://logicalhacking.com/publications/brucker.ea-aniketos-compliance-2014/
[13]
M. Asim, A. Yautsiukhin, A. D. Brucker, B. Lempereur, and Q. Shi, “Security policy monitoring of composite services,” in Secure and trustworthy service composition: The aniketos approach, A. D. Brucker, F. Dalpiaz, P. Giorgini, P. H. Meland, and E. Rios, Eds. Heidelberg: Springer-Verlag, 2014, pp. 192–202. doi: 10.1007/978-3-319-13518-2_13. Author copy: http://logicalhacking.com/publications/asim.ea-aniketos-monitoring-2014/
[14]
A. D. Brucker, F. Dalpiaz, P. Giorgini, P. H. Meland, and E. Rios, Eds., Secure and trustworthy service composition: The aniketos approach. Heidelberg: Springer-Verlag, 2014. doi: 10.1007/978-3-319-13518-2.