Navigation View


Defines the navigation flow of the application and navigational access control policies. The former shows which possibilities of navigation exist in a certain context. The latter specifies which roles are allowed to navigate to a specific state and the action taken in case access cannot be granted. In a web application such actions can be, e.g., to logout the user and to redirect to the login form or just to display an error message. Furthermore, secure connections between server and browser are modeled, too.
  • Security Aspects

    • Authentication

      Enables users to log into a system.
      Specification Elements:
      IsHome
      Threats:
      Spoofing
      Elevation of Privileges
    • Reauthentication

      After a certain time of inactivity, users need to authenticate themselves again.
      Specification Elements:
      ReAuth
      Threats:
      Spoofing
      Elevation of Privileges
    • Secure Connections

      Can be used to ensure the confidentiality, integrity and freshness of all user’s request as well as of all response of the system.
      Specification Elements:
      TransmissionType
      Threats:
      Tampering with Data
      Repudiation
      Information Disclosure
      Denial of Service
      Elevation of Privileges
    • Under Attack Mode

      A dynamic protection against attempts of compromising the systems functionality, as the system reacts accordingly and reduces the attackers possibilities.
      Specification Elements:
      NoAccessInMode
      Threats:
      Tampering with Data
      Repudiation
      Information Disclosure
      Denial of Service
      Elevation of Privileges

    Specification Elements