Thesis author: Leon Gawdi
Architectural and design-level decisions are an increasingly recognized source of security vulnerabilities in modern software systems. This highlights the need to integrate security considerations into early design phases. Existing UML-based security modeling approaches such as UMLsec, SecureUML, and CARiSMA address verification, access control, and compliance analysis, but none is primarily concerned with structuring the security architecture description as an integrated, traceable part of the overall architecture description. While a prior contribution to the Security-Centric Architecture Modelling research project introduced a novel conceptual modeling approach to this integration problem, it has remained without operationalization in an established modeling language, preventing both empirical evaluation and practical adoption. This thesis presents SA-UML, a UML profile which operationalizes that approach by extending UML with stereotypes, tagged values, and OCL constraints, establishing a structurally complete tracing chain from security requirements through design solutions to architectural countermeasures. The profile is demonstrated through structural and behavioral views of a fictitious web-based document portal and evaluated in a questionnaire study with n = 27 participants comparing SA-UML against standard UML across the dimensions of effciency, effectiveness, and perceived usefulness. Participants completed security-related tasks approximately 30% faster with SA-UML (t(26) = 2.81, p = 0.005, dz = 0.54), and rated the profile as significantly useful across all Likert items (p < 0.001, r > 0.5), while no significant difference in task scores was found. These results provide initial evidence that SA-UML supports practitioners in understanding security architecture descriptions, and motivate future evaluations on larger, industry-relevant systems as well as the development of a dedicated conformance-enforcing modeling tool
