ArticleslgStudy

engineering

Model-driven security

Model-driven security is a engineering topic covered in the lgStudy science library. This page brings together a partial reference excerpt, illustrations, worked examples, real-world applications and a short study plan, so you can understand Model-driven security rather than just read about it. In short: Model-driven security (MDS) means applying model-driven approaches (and especially the concepts behind model-driven software development) to security. Development of the concept The general concept of Model-driven security in its earliest forms has been around since the late 1990s (mostly in university research), and was first commercialized around 2002.

Key takeaways

  • Model-driven security belongs to engineering; place it in that map before memorising details.
  • Learn the definition first, then one example that makes the definition concrete.
  • Connect Model-driven security to a quantity you can measure, compute or draw — that is where exam questions come from.
  • Reproduce the core statement of Model-driven security from memory before moving on to harder problems.

Reference excerpt

Model-driven security (MDS) means applying model-driven approaches (and especially the concepts behind model-driven software development) to security.

Development of the concept The general concept of Model-driven security in its earliest forms has been around since the late 1990s (mostly in university research), and was first commercialized around 2002. There is also a body of later scientific research in this area, which continues to this day. A more specific definition of Model-driven security specifically applies model-driven approaches to automatically generate technical security implementations from security requirements models. In particular, "Model driven security (MDS) is the tool supported process of modelling security requirements at a high level of abstraction, and using other information sources available about the system (produced by other stakeholders). These inputs, which are expressed in Domain Specific Languages (DSL), are then transformed into enforceable security rules with as little human intervention as possible. MDS explicitly also includes the run-time security management (e.g. entitlements/authorisations), i.e. run-time enforcement of the policy on the protected IT systems, dynamic policy updates and the monitoring of policy violations." Model-driven security is also well-suited for automated auditing, reporting, documenting, and analysis (e.g. for compliance and accreditation), because the relationships between models and technical security implementations are traceably defined through the model-transformations.

Opinions of industry analysts Several industry analyst sources state that MDS "will have a significant impact as information security infrastructure is required to become increasingly real-time, automated and adaptive to changes in the organisation and its environment". Many information technology architectures today are built to support adaptive changes (e.g. Service Oriented Architectures (SOA) and so-called Platform-as-a-Service "mashups" in cloud computing), and information security infrastructure will need to support that adaptivity ("agility"). The term DevOpsSec (see DevOps) is used by some analysts equivalent to model-driven security.

Effects of MDS Because MDS automates the generation and re-generation of technical security enforcement from generic models, it:

enables SOA agility reduces complexity (and SOA security complexity) increases policy flexibility supports rich application security policies supports workflow context sensitive security policies can auto-generate SOA infrastructure security policies supports reuse between SOA stakeholders minimises human errors can auto-generate domain boundary security policies helps enable SOA assurance accreditation (covered in ObjectSecurity’s MDSA eBook)

Implementations of MDS Apart from academic proof-of-concept developments, the only commercially available full implementations of model-driven security (for authorization management policy automation) include ObjectSecurity OpenPMF, which earned a listing in Gartner's "Cool Vendor" report in 2008 and has been advocated by a number of organizations (e.g. U.S. Navy ) as a means to make authorization policy management easier and more automated.

See also Model-driven architecture Data-driven security Authorization Attribute based access control XACML Role-based access control Mandatory access control Discretionary access control

References

Worked examples

Example 1 — a first encounter with Model-driven security

Start with the simplest possible case. Write down what Model-driven security claims or describes in one sentence, then invent the smallest concrete situation in which that sentence is true. In engineering, the smallest case is usually a single object, a single equation or a single measurement. Check that every symbol or term in your sentence has a meaning in that case.

Example 2 — changing one variable

Take the situation from Example 1 and change exactly one quantity: double it, halve it, or set it to zero. Predict what should happen to Model-driven security before you calculate. Comparing your prediction with the result is the fastest way to find out whether you understand the idea or only the words.

Example 3 — an exam-style question

Typical questions about Model-driven security ask you to (a) state it precisely, (b) apply it to given data, and (c) explain a limitation. Practise writing all three answers in under five minutes; the third part is what separates a full-mark answer from an average one.

Applications of Model-driven security

In research
Model-driven security appears in engineering research whenever the underlying quantities have to be modelled precisely. Papers usually cite it as a starting assumption and then explore where it breaks down.
In technology and industry
Engineering practice reuses Model-driven security in design rules, simulations and safety margins. Knowing the idea lets you read a specification sheet and understand why the numbers look the way they do.
In the classroom
Model-driven security is common in secondary-school and first-year university syllabi. It links to neighbouring topics Cybersecurity engineering, so understanding it makes those chapters shorter.
In everyday life
Look for Model-driven security outside the textbook — in sport, cooking, traffic, electronics or the sky above you. An example you found yourself is remembered far longer than one you were given.
Ask Teacher Smith questions about this articleOpens your AI tutor with a question about “Model-driven security” →

Affiliate

Preply — study more efficiently by working with a personal tutor. 50% off.

How to study Model-driven security in 20 minutes

  1. Read the reference excerpt below once, without taking notes.
  2. Close the page and write down what Model-driven security means in your own words.
  3. Compare your version with the excerpt and mark what you missed.
  4. Work through the three examples above with pen and paper.
  5. Explain Model-driven security out loud to somebody else — or to Teacher Smith in the lgStudy chat.

Frequently asked questions

What is Model-driven security in simple terms?

Model-driven security (MDS) means applying model-driven approaches (and especially the concepts behind model-driven software development) to security. Development of the concept The general concept of Model-driven security in its earliest forms has been around since the late 1990s (mostly in univer…

Why does Model-driven security matter?

Because it connects several engineering ideas at once: it gives you a definition you can apply, a quantity you can calculate, and a way to check whether a result is plausible.

How should I study Model-driven security?

Read the excerpt, restate it from memory, then work through the examples and applications listed on this page. The five-step study plan above takes about twenty minutes.

What does this page cover?

It gives you a compact reference excerpt plus original lgStudy explanations, examples, applications and study material on Model-driven security.

Tags

  • Cybersecurity engineering

Keep exploring