Debido al alto tráfico generado por robots, aplicamos límites en el número de peticiones permitidas por cliente y bloqueos por IP automáticos. Si haces un uso legítimo y estás teniendo problemas, avísanos para reevaluar nuestras políticas de bloqueo. Disculpa las molestias.

Resumen:
Automatic Verification and Diagnosis of Security Risk Assessments in Business Process Models

bs.conference.acronymJCIS
bs.conference.nameJornadas de Ciencia e Ingeniería de Servicios (JCIS)
bs.edition.date2019-09-02
bs.edition.locationCáceres
bs.edition.nameXV Jornadas de Ciencia e Ingeniería de Servicios (JCIS 2019)
bs.proceedings.editorTorres Bosch, V
bs.proceedings.nameActas de las XV Jornadas de Ciencia e Ingeniería de Servicios (JCIS 2019)
dc.contributor.affiliationUniversity of Seville, Spain
dc.contributor.affiliationUniversidad Loyola Andalucía, Spain
dc.contributor.affiliationUniversity of Seville, Spain
dc.contributor.affiliationUniversity of Seville, Spain
dc.contributor.authorVarela Vaca, Ángel Jesús
dc.contributor.authorParody, Luisa
dc.contributor.authorMartínez-Gasca, Rafael
dc.contributor.authorGómez López, María Teresa
dc.contributor.emailajvarela@us.es
dc.contributor.emailmlparody@uloyola.es
dc.contributor.emailgasca@us.es
dc.contributor.emailmaytegomez@us.es
dc.contributor.signatureVarela Vaca, Angel Jesus
dc.contributor.signatureParody, Luisa
dc.contributor.signatureGasca, Rafael M.
dc.contributor.signatureGómez López, Maria Teresa
dc.date.accessioned2019-09-02T00:00:00Z
dc.date.available2019-09-02T00:00:00Z
dc.date.issued2019-09-02
dc.description.abstractOrganizations execute daily activities to meet their objectives. The performance of these activities can be fundamental for achieving a business objective, but they also imply the assumption of certain security risks that might go against a company's security policies. A risk may be defined as the effects of uncertainty on the achievement of the goals of a company, some of which can be associated with security aspects (e.g., data corruption or data leakage). The execution of the activities can be choreographed using business processes models, in which the risk of the entire business process model derives from a combination of the single activity risks (executed in an isolated manner). In this paper, the problem of automatic security risk management in the current BPMS is addresses. First, a formalization of the risk elements according to process models is included. These elements are supported as a BPMN 2.0 extension of risk information that is analyzed to determine nonconformance regarding risk goals. In addition, a diagnosis of the risk associated with the activity responsible for the nonconformance is also carried out. To this end, the proposal applies mechanisms based on the model-based diagnosis in which activities are in nonconformance with regard to the acceptable level of risk. The automation of diagnosis is carried out using artificial intelligence techniques based on constraint programming. The proposal is supported by the implementation of a plug-in that enables the graphical specification of the extension and the automation of the verification and diagnosis process. To the best of our knowledge, this is the first published work that addresses the risk-aware design of business processes with automatic techniques.
dc.identifier.citationVarela Vaca, A. J., Parody, L., Gasca, R. M., Gómez López, M. T.: Automatic Verification and Diagnosis of Security Risk Assessments in Business Process Models. In: Torres Bosch, V. (ed.) Actas de las XV Jornadas de Ciencia e Ingeniería de Servicios (JCIS 2019). Sistedes (2019). https://hdl.handle.net/11705/JCIS/2019/014
dc.identifier.citation-bibtex@inproceedings{11705:JCIS:2019:014, title = {{Automatic Verification and Diagnosis of Security Risk Assessments in Business Process Models}}, author = {Varela Vaca, A. J. and Parody, L. and Gasca, R. M. and G\'{o}mez L\'{o}pez, M. T.}, url = {https://hdl.handle.net/11705/JCIS/2019/014}, crossref = {11705:JCIS:2019} } @proceedings{11705:JCIS:2019, title = {{Actas de las XV Jornadas de Ciencia e Ingenier\'{i}a de Servicios (JCIS 2019)}}, author = {Torres Bosch, V.}, year = {2019}, publisher = {{Sistedes}}, }
dc.identifier.sistedes11705/JCIS/2019/014
dc.publisherSistedes
dc.relation.ispartofActas de las XV Jornadas de Ciencia e Ingeniería de Servicios (JCIS 2019)
dc.rights.licenseCC BY 4.0
dc.rights.urihttps://creativecommons.org/licenses/by/4.0/
dc.subjectBusiness Process Management
dc.subjectBusiness Process Model
dc.subjectConstraint Programming
dc.subjectModel-based Diagnosis
dc.subjectSecurity-Risk Assessment
dc.titleAutomatic Verification and Diagnosis of Security Risk Assessments in Business Process Models
dspace.entity.typeResumen
relation.isAuthorOfAbstracte1dde63c-42fb-4503-ae13-64200e263938
relation.isAuthorOfAbstract88878a7e-f0be-4343-b0aa-8efda512ccd6
relation.isAuthorOfAbstract91d3a839-3999-474e-a94f-52eb65ba4d78
relation.isAuthorOfAbstract34f1bc36-d5cb-49dc-a9c9-93a44c231d71
relation.isAuthorOfAbstract.latestForDiscoverye1dde63c-42fb-4503-ae13-64200e263938

Archivos

Bloque original

Mostrando 1 - 1 de 1
Cargando...
Miniatura
Nombre:
11705-JCIS-2019-014.pdf
Tamaño:
98.75 KB
Formato:
Adobe Portable Document Format