Mostrar el registro sencillo

dc.contributor.authorBlanco Bueno, Carlos 
dc.contributor.authorGarcía Saiz, Diego 
dc.contributor.authorRosado, David
dc.contributor.authorSantos Olmo, Antonio
dc.contributor.authorPeral, Jesús
dc.contributor.authorMaté, Alejandro
dc.contributor.authorTrujillo, Juan
dc.contributor.authorFernández Medina, Eduardo
dc.contributor.otherUniversidad de Cantabriaes_ES
dc.date.accessioned2024-03-21T14:59:39Z
dc.date.available2024-03-21T14:59:39Z
dc.date.issued2023
dc.identifier.otherPID2020-112540RB-C42
dc.identifier.otherPID2020-112540RB-C43
dc.identifier.urihttps://hdl.handle.net/10902/32390
dc.description.abstractThe importance of data security is currently increasing owing to the number of data transactions that are continuously taking place. Large amounts of data are generated, stored, modified and transferred every second, signifying that databases require an appropriate capacity, control and protection that will enable them to maintain a secure environment for so much data. Big Data is becoming a prominent trend in our society, and increasing amounts of data, including sensitive and personal information, are being loaded into NoSQL and other Big Data technologies for analysis and processing. However, current security approaches do not take into account the special characteristics of these technologies, leaving sensitive and personal data unprotected and consequently risking considerable financial losses and brand damage. In this paper, we focus on NoSQL document databases and present a proposal for the design and implementation of security policies in this type of databases. We first follow the concept of security by design in order to propose a metamodel that allows the specification of both the structure and the security policies required for document databases. We also define an implementation model by analysing the implementation features provided by a specific NoSQL document database management system (MongoDB). Having obtained the design and implementation models, we follow the model-driven development philosophy and propose a set of transformation rules that allow the automatic generation of the final implementation of security policies. We additionally provide a technological solution in which the Eclipse Modelling Framework environment is employed in order to implement both the design metamodel (Emfatic) and the transformations (Epsilon, EGL). Finally, we apply the proposed framework to a case study carried out in the airport domain. This proposal, in addition to saving development time and costs, generates more robust solutions by considering security by design. This, therefore, abstracting the designer from both specific aspects of the target tool and having to choose the best strategies for the implementation of security policies.es_ES
dc.description.sponsorshipThis work has been developed within the AETHER-UCLM (PID2020- 112540RB-C42), AETHER-UA (PID2020-112540RB-C43) and PRECONI4 (TIN2017-86520-C3-3-R) projects funded by ‘‘Ministerio de Ciencia e Innovación, Spain’’, and the AURORA (SBPLY/21/180501/000079) and GENESIS (SBPLY/17/180501/000202) projects funded by ‘‘Consejería de Educación, Cultura 𝑦 Deportes, Junta de Comunidades de Castilla-La Mancha, Fondo Europeo de Desarrollo Regional FEDER.
dc.language.isoenges_ES
dc.publisherElsevieres_ES
dc.rights© 2022 The Authors. Published by Elsevier Ltd. This is an open access article under the CC BY-NC-ND licensees_ES
dc.rights.urihttp://creativecommons.org/licenses/by-nc-nd/4.0/*
dc.sourceJournal of Information Security and Applications, 2022, 65, 103120es_ES
dc.subject.otherSecurityes_ES
dc.subject.otherDesignes_ES
dc.subject.otherNoSQLes_ES
dc.subject.otherDocument Databaseses_ES
dc.subject.otherModel Driven Engineeringes_ES
dc.titleSecurity policies by design in NoSQL document databaseses_ES
dc.typeinfo:eu-repo/semantics/conferenceObjectes_ES
dc.relation.publisherVersionhttps://doi.org/10.1016/j.jisa.2022.103120es_ES
dc.rights.accessRightsopenAccesses_ES
dc.relation.projectIDinfo:eu-repo/grantAgreement/AEI/Plan Estatal de Investigación Científica y Técnica y de Innovación 2017-2020/PID2020-112540RB-C42/ES/UNA APROXIMACION HOLISTICA DE SMART DATA PARA EL ANALISIS DE DATOS GUIADO POR EL CONTEXTO CENTRADA EN LA CALIDAD Y LA SEGURIDAD /
dc.relation.projectIDinfo:eu-repo/grantAgreement/AEI/Plan Estatal de Investigación Científica y Técnica y de Innovación 2017-2020/PID2020-112540RB-C43/ES/UNA APROXIMACION HOLISTICA DE SMART DATA PARA EL ANALISIS DE DATOS GUIADO POR EL CONTEXTO: APRENDIZAJE AUTOMATICO INTELIGENTE PARA EL MODELADO Y ANALISIS DEL NEGOCIO/
dc.identifier.DOI10.1016/j.jisa.2022.103120
dc.type.versionpublishedVersiones_ES


Ficheros en el ítem

Thumbnail

Este ítem aparece en la(s) siguiente(s) colección(ones)

Mostrar el registro sencillo

© 2022 The Authors. Published by Elsevier Ltd. This is an open access article under the CC BY-NC-ND licenseExcepto si se señala otra cosa, la licencia del ítem se describe como © 2022 The Authors. Published by Elsevier Ltd. This is an open access article under the CC BY-NC-ND license