Connecting security properties to implementation artifacts

Design a representation of security features that connects security requirements, assumptions, and guarantees to the concrete code, configuration, and deployment artifacts that implement them.

Background

Security feature location requires an abstraction between design-level security concepts—such as security properties, threat models, and security principles—and concrete implementations. Because security properties generally emerge from compositions of multiple security features rather than mapping one-to-one to individual artifacts, the paper identifies the required connection as unresolved.

References

But how do we connect these design-level security properties to the concrete artifacts that implement them?

The Security Feature Location Problem  (2609.04899 - Hermann et al., 4 Sep 2026) in Section 5, Research Challenges, subsection “C2.1: How can we represent security features?”

But which aspects of this security-specific context are relevant to a particular task, and how should it be made accessible to developers?

The Security Feature Location Problem  (2609.04899 - Hermann et al., 4 Sep 2026) in Section 5, Research Challenges, subsection “C2.4: How can we contextualize security feature locations for security tasks?”