Show simple item record

Automatic Verification and Diagnosis of Security Risk Assessments in Business Process Models

dc.contributor.authorVarela Vaca, Ángel Jesús
dc.contributor.authorParody Núñez, María Luisa
dc.contributor.authorMartínez Gasca, Rafael
dc.contributor.authorGómez-López, María Teresa
dc.date.accessioned2024-06-28T08:21:36Z
dc.date.available2024-06-28T08:21:36Z
dc.date.issued2019-02-25
dc.identifier.citationVarela Vaca, Angel & Parody, Luisa & Gasca, Rafael & Gómez López, María Teresa. (2019). Automatic Verification and Diagnosis of Security Risk Assessments in Business Process Models. IEEE Access. PP. 1-1. 10.1109/ACCESS.2019.2901408.es
dc.identifier.issn2169-3536
dc.identifier.urihttps://hdl.handle.net/20.500.12412/5920
dc.description.abstractOrganizations execute daily activities to meet their objectives. The performance of these activities can be fundamental for achieving a business objective, but they also imply the assumption of certain security risks that might go against a company’s security policies. A risk may be defined as the effects of uncertainty on the achievement of the goals of a company, some of which can be associated with security aspects (e.g., data corruption or data leakage). The execution of the activities can be choreographed using business processes models, in which the risk of the entire business process model derives from a combination of the single activity risks (executed in an isolated manner). In this paper, a risk assessment method is proposed to enable the analysis and evaluation of a set of activities combined in a business process model to ascertain whether the model conforms to the security-risk objectives. To achieve this objective, we use a business process extension with security-risk information to (1) define an algorithm to verify the level of risk of process models; (2) design an algorithm to diagnose the risk of the activities that fail to conform to the level of risk established in security-risk objectives; and (3) the implementation of a tool that supports the described proposal. In addition, a real case study is presented, and a set of scalability benchmarks of and performance analysis are carried out in order to check the usefulness and suitability of automation of the algorithms.es
dc.language.isoenges
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 Internacional*
dc.rights.urihttp://creativecommons.org/licenses/by-nc-nd/4.0/*
dc.titleAutomatic Verification and Diagnosis of Security Risk Assessments in Business Process Modelses
dc.typearticlees
dc.identifier.doi10.1109/ACCESS.2019.2901408
dc.journal.titleIEEE Accesses
dc.page.initial26448es
dc.page.final26465es
dc.relation.projectIDThis work has been partially funded by the Ministry of Science and Technology of Spain by ECLIPSE and SEQUOIA (TIN2015-63502-C3-2-R) projects, the European Regional Development Fund (ERDF/FEDER), and the Cátedra of Telefónica.es
dc.rights.accessRightsopenAccesses
dc.subject.keywordBusiness process managementes
dc.subject.keywordModel security-risk assessmentes
dc.subject.keywordModel-based diagnosis constraint programminges
dc.volume.number7es


Files in this item

This item appears in the following Collection(s)

Show simple item record

Attribution-NonCommercial-NoDerivatives 4.0 Internacional
Except where otherwise noted, this item's license is described as Attribution-NonCommercial-NoDerivatives 4.0 Internacional