SecArchUnit Extending ArchUnit to support validation of security architectural constraints

dc.contributor.authorRANDEVIK, MARCUS
dc.contributor.authorOLSON, PATRIK
dc.contributor.departmentChalmers tekniska högskola / Institutionen för data och informationstekniksv
dc.contributor.examinerChaudron, Michel
dc.contributor.supervisorScandariato, Riccardo
dc.date.accessioned2021-03-02T09:24:08Z
dc.date.available2021-03-02T09:24:08Z
dc.date.issued2020sv
dc.date.submitted2020
dc.description.abstractThe architecture of a software system heavily influences the level of security achieved. However, a perfectly designed architecture does not provide any security if the implementation does not conform to the constraints. Adhering to a defined architecture is easier said than done as the representation of its design often requires manual labor to validate the conformance of the implementation. Previous attempts at solving the issue of creating a representation that allows for automatic conformance checking has failed to gain adoption, perhaps due to the disparity between models and code. In this thesis, we present our investigation and extension of the ArchUnit library to support the validation of security architectural constraints. In contrast to previously proposed approaches, ArchUnit represents architectural constraints via rules that can be validated using conventional unit test runners. We compare our extension of ArchUnit, called SecArchUnit, to both SonarQube and PMD to distinguish any difference in their ability to detect violations of constrains as well as their appropriateness of expressing architectural constraints. Our results show that SecArchUnit was able to detect a wider variety of constraints and provides an interface more suitable for defining constraints at the architectural level.sv
dc.identifier.coursecodeMPSOFsv
dc.identifier.urihttps://hdl.handle.net/20.500.12380/302240
dc.language.isoengsv
dc.setspec.uppsokTechnology
dc.subjectSoftware Architecturesv
dc.subjectArchitectural Conformancesv
dc.subjectStatic Analysissv
dc.subjectSecuritysv
dc.titleSecArchUnit Extending ArchUnit to support validation of security architectural constraintssv
dc.type.degreeExamensarbete för masterexamensv
dc.type.uppsokH
local.programmeComputer systems and networks (MPCSN), MSc

Ladda ner

Original bundle

Visar 1 - 1 av 1
Hämtar...
Bild (thumbnail)
Namn:
CSE 20-85 Olson Randevik.pdf
Storlek:
1.86 MB
Format:
Adobe Portable Document Format
Beskrivning:

License bundle

Visar 1 - 1 av 1
Hämtar...
Bild (thumbnail)
Namn:
license.txt
Storlek:
1.14 KB
Format:
Item-specific license agreed upon to submission
Beskrivning: