Online compliance monitoring of service landscapes

J.M.E.M. Werf, van der, H.M.W. Verbeek

Research output: Chapter in Book/Report/Conference proceedingConference contributionAcademicpeer-review

6 Citations (Scopus)

Abstract

Today, it is a challenging task to keep a service application running over the internet safe and secure. Based on a collection of security requirements, a so-called golden configuration can be created for such an application. When the application has been configured according to this golden configuration, it is assumed that it satisfies these requirements, that is, that it is safe and secure. This assumption is based on the best practices that were used for creating the golden configuration, and on assumptions like that nothing out-of-the-ordinary occurs. Whether the requirements are actually violated, can be checked on the traces that are left behind by the configured service application. Today’s applications typically log an enormous amount of data to keep track of everything that has happened. As such, such an event log can be regarded as the ground truth for the entire application: A security requirement is violated if and only if it shows in the event log. This paper introduces the ProMSecCo tool, which has been built to check whether the security requirements that have been used to create the golden configuration are violated by the event log as generated by the configured service application.
Original languageEnglish
Title of host publicationBusiness Process Management Workshops (BPM 2014 International Workshops, Eindhoven, The Netherlands, September 7-8, 2014, Revised Papers)
EditorsF. Fournier, J. Mendling
Place of PublicationBerlin
PublisherSpringer
Pages89-95
ISBN (Print)978-3-319-15894-5
DOIs
Publication statusPublished - 2015

Publication series

NameLecture Notes in Business Information Processing
Volume202
ISSN (Print)1865-1348

Fingerprint

Dive into the research topics of 'Online compliance monitoring of service landscapes'. Together they form a unique fingerprint.

Cite this