@conference{busch-bir-2011, author = "Marianne Busch and Alexander Knapp and Nora Koch", abstract = "Secure web information systems are becoming increasingly important due to rising cybercrime as well as the growing awareness of data privacy. Besides authentication and confidential connections, both data access control and navigational access control are the most relevant security features in this field. Adding such security features, however, to already implemented web applications is an error-prone task. Our approach enables web engineers to model security issues in an early phase of the development process. We demonstrate the integration for the UML-based Web Engineering (UWE) method. The approach supports the engineer by providing means to model navigational security with a plugin in a UML modeling tool. Additionally, the models can be used for the verification of web systems and security properties, such as reachability of navigation nodes in general and of those that are restricted to authorized users.", booktitle = "10th International Conference on Business Perspectives in Informatics Research", doi = "http://dx.doi.org/10.1007/978-3-642-24511-4_19", editor = "Janis Grabis and Marite Kirikova", note = "PARTNERS: LMU and partner outside NESSoS (Augsburg); PROJECTS: NESSoS; NoTier cites:5", publisher = "Springer Verlag", series = "LNBIP", title = "{M}odeling {S}ecure {N}avigation in {W}eb {I}nformation {S}ystems", year = "2011", }