Automatic Verification and Diagnosis of Security Risk Assessments in Business Process Models

Organizations execute daily activities to meet their objectives. The performance of these activities can be fundamental for achieving a business objective, but they also imply the assumption of certain security risks that might go against a company's security policies. A risk may be defined as...

Full description

Bibliographic Details
Main Authors: Angel J. Varela-Vaca, Luisa Parody, Rafael M. Gasca, Maria T. Gomez-Lopez
Format: Article
Language:English
Published: IEEE 2019-01-01
Series:IEEE Access
Subjects:
Online Access:https://ieeexplore.ieee.org/document/8651587/
id doaj-d7630e38ff31488da6de7649abde70fa
record_format Article
spelling doaj-d7630e38ff31488da6de7649abde70fa2021-03-29T22:29:59ZengIEEEIEEE Access2169-35362019-01-017264482646510.1109/ACCESS.2019.29014088651587Automatic Verification and Diagnosis of Security Risk Assessments in Business Process ModelsAngel J. Varela-Vaca0https://orcid.org/0000-0001-9953-6005Luisa Parody1Rafael M. Gasca2Maria T. Gomez-Lopez3Department of Languages and Computer Systems, Universidad de Sevilla, Seville, SpainDepartment of Quantitative Methods, Universidad Loyola Andalucía, Seville, SpainDepartment of Languages and Computer Systems, Universidad de Sevilla, Seville, SpainDepartment of Languages and Computer Systems, Universidad de Sevilla, Seville, SpainOrganizations execute daily activities to meet their objectives. The performance of these activities can be fundamental for achieving a business objective, but they also imply the assumption of certain security risks that might go against a company's security policies. A risk may be defined as the effects of uncertainty on the achievement of the goals of a company, some of which can be associated with security aspects (e.g., data corruption or data leakage). The execution of the activities can be choreographed using business processes models, in which the risk of the entire business process model derives from a combination of the single activity risks (executed in an isolated manner). In this paper, a risk assessment method is proposed to enable the analysis and evaluation of a set of activities combined in a business process model to ascertain whether the model conforms to the security-risk objectives. To achieve this objective, we use a business process extension with security-risk information to: 1) define an algorithm to verify the level of risk of process models; 2) design an algorithm to diagnose the risk of the activities that fail to conform to the level of risk established in security-risk objectives; and 3) the implementation of a tool that supports the described proposal. In addition, a real case study is presented, and a set of scalability benchmarks of performance analysis is carried out in order to check the usefulness and suitability of automation of the algorithms.https://ieeexplore.ieee.org/document/8651587/Business process management business process model security-risk assessment model-based diagnosis constraint programming
collection DOAJ
language English
format Article
sources DOAJ
author Angel J. Varela-Vaca
Luisa Parody
Rafael M. Gasca
Maria T. Gomez-Lopez
spellingShingle Angel J. Varela-Vaca
Luisa Parody
Rafael M. Gasca
Maria T. Gomez-Lopez
Automatic Verification and Diagnosis of Security Risk Assessments in Business Process Models
IEEE Access
Business process management business process model security-risk assessment model-based diagnosis constraint programming
author_facet Angel J. Varela-Vaca
Luisa Parody
Rafael M. Gasca
Maria T. Gomez-Lopez
author_sort Angel J. Varela-Vaca
title Automatic Verification and Diagnosis of Security Risk Assessments in Business Process Models
title_short Automatic Verification and Diagnosis of Security Risk Assessments in Business Process Models
title_full Automatic Verification and Diagnosis of Security Risk Assessments in Business Process Models
title_fullStr Automatic Verification and Diagnosis of Security Risk Assessments in Business Process Models
title_full_unstemmed Automatic Verification and Diagnosis of Security Risk Assessments in Business Process Models
title_sort automatic verification and diagnosis of security risk assessments in business process models
publisher IEEE
series IEEE Access
issn 2169-3536
publishDate 2019-01-01
description Organizations execute daily activities to meet their objectives. The performance of these activities can be fundamental for achieving a business objective, but they also imply the assumption of certain security risks that might go against a company's security policies. A risk may be defined as the effects of uncertainty on the achievement of the goals of a company, some of which can be associated with security aspects (e.g., data corruption or data leakage). The execution of the activities can be choreographed using business processes models, in which the risk of the entire business process model derives from a combination of the single activity risks (executed in an isolated manner). In this paper, a risk assessment method is proposed to enable the analysis and evaluation of a set of activities combined in a business process model to ascertain whether the model conforms to the security-risk objectives. To achieve this objective, we use a business process extension with security-risk information to: 1) define an algorithm to verify the level of risk of process models; 2) design an algorithm to diagnose the risk of the activities that fail to conform to the level of risk established in security-risk objectives; and 3) the implementation of a tool that supports the described proposal. In addition, a real case study is presented, and a set of scalability benchmarks of performance analysis is carried out in order to check the usefulness and suitability of automation of the algorithms.
topic Business process management business process model security-risk assessment model-based diagnosis constraint programming
url https://ieeexplore.ieee.org/document/8651587/
work_keys_str_mv AT angeljvarelavaca automaticverificationanddiagnosisofsecurityriskassessmentsinbusinessprocessmodels
AT luisaparody automaticverificationanddiagnosisofsecurityriskassessmentsinbusinessprocessmodels
AT rafaelmgasca automaticverificationanddiagnosisofsecurityriskassessmentsinbusinessprocessmodels
AT mariatgomezlopez automaticverificationanddiagnosisofsecurityriskassessmentsinbusinessprocessmodels
_version_ 1724191557164204032