Mostrar el registro sencillo del ítem

Artículo

dc.creatorVarela Vaca, Ángel Jesúses
dc.creatorParody Núñez, María Luisaes
dc.creatorMartínez Gasca, Rafaeles
dc.creatorGómez López, María Teresaes
dc.date.accessioned2020-06-06T15:43:26Z
dc.date.available2020-06-06T15:43:26Z
dc.date.issued2019
dc.identifier.citationVarela Vaca, Á.J., Parody Núñez, M.L., Martínez Gasca, R. y Gómez López, M.T. (2019). Automatic Verification and Diagnosis of Security Risk Assessments in Business Process Models. IEEE Access, 7, 26448-26465.
dc.identifier.issn2169-3536es
dc.identifier.urihttps://hdl.handle.net/11441/97496
dc.description.abstractOrganizations execute daily activities to meet their objectives. The performance of these activities can be fundamental for achieving a business objective, but they also imply the assumption of certain security risks that might go against a company's security policies. A risk may be de ned as the effects of uncertainty on the achievement of the goals of a company, some of which can be associated with security aspects (e.g., data corruption or data leakage). The execution of the activities can be choreographed using business processes models, in which the risk of the entire business process model derives from a combination of the single activity risks (executed in an isolated manner). In this paper, a risk assessment method is proposed to enable the analysis and evaluation of a set of activities combined in a business process model to ascertain whether the model conforms to the security-risk objectives. To achieve this objective, we use a business process extension with security-risk information to: 1) de ne an algorithm to verify the level of risk of process models; 2) design an algorithm to diagnose the risk of the activities that fail to conform to the level of risk established in security-risk objectives; and 3) the implementation of a tool that supports the described proposal. In addition, a real case study is presented, and a set of scalability benchmarks of performance analysis is carried out in order to check the usefulness and suitability of automation of the algorithms.es
dc.description.sponsorshipMinisterio de Ciencia y Tecnología TIN2015-63502-C3-2-Res
dc.formatapplication/pdfes
dc.format.extent18es
dc.language.isoenges
dc.publisherIEEE Computer Societyes
dc.relation.ispartofIEEE Access, 7, 26448-26465.
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 Internacional*
dc.rights.urihttp://creativecommons.org/licenses/by-nc-nd/4.0/*
dc.subjectBusiness process managementes
dc.subjectBusiness Process Modeles
dc.subjectSecurity-risk assessmentes
dc.subjectModel-based diagnosises
dc.subjectConstraint programminges
dc.titleAutomatic Verification and Diagnosis of Security Risk Assessments in Business Process Modelses
dc.typeinfo:eu-repo/semantics/articlees
dcterms.identifierhttps://ror.org/03yxnpp24
dc.type.versioninfo:eu-repo/semantics/submittedVersiones
dc.rights.accessRightsinfo:eu-repo/semantics/openAccesses
dc.contributor.affiliationUniversidad de Sevilla. Departamento de Lenguajes y Sistemas Informáticoses
dc.relation.projectIDTIN2015-63502-C3-2-Res
dc.relation.publisherversionhttps://ieeexplore.ieee.org/document/8651587es
dc.identifier.doi10.1109/ACCESS.2019.2901408es
dc.journaltitleIEEE Accesses
dc.publication.volumen7es
dc.publication.initialPage26448es
dc.publication.endPage26465es
dc.contributor.funderMinisterio de Ciencia Y Tecnología (MCYT). Españaes

FicherosTamañoFormatoVerDescripción
Automatic Verification and ...2.234MbIcon   [PDF] Ver/Abrir  

Este registro aparece en las siguientes colecciones

Mostrar el registro sencillo del ítem

Attribution-NonCommercial-NoDerivatives 4.0 Internacional
Excepto si se señala otra cosa, la licencia del ítem se describe como: Attribution-NonCommercial-NoDerivatives 4.0 Internacional