4 papers
"Shifting Access Control Left" using Asset and Goal Models
Shamal Faily
Access control needs have broad design implications, but access control specifications may be elicited before, during, or after these needs are captured. Because access control kno…
Biting the CHERI bullet: Blockers, Enablers and Security Implications of CHERI in Defence
Shamal Faily
There is growing interest in securing the hardware foundations software stacks build upon. However, before making any investment decision, software and hardware supply chain stakeh…
Identifying Implicit Vulnerabilities through Personas as Goal Models
Shamal Faily, Claudia Iacob, Raian Ali +1
When used in requirements processes and tools, personas have the potential to identify vulnerabilities resulting from misalignment between user expectations and system goals. Typic…
Contextualisation of Data Flow Diagrams for security analysis
Shamal Faily, Riccardo Scandariato, Adam Shostack +2
Data flow diagrams (DFDs) are popular for sketching systems for subsequent threat modelling. Their limited semantics make reasoning about them difficult, but enriching them endange…