Specifying Deception Requirements with iStar
Resumo
Cybersecurity plays a central role in software development. Deception-based defense is a cybersecurity subfield in which actions are intentionally employed to cause misrepresentation and induce erroneous inferences on attackers. Deception can be employed at different levels of computation, from network to application-level, which demands careful planning and coordination between multiple strategies and tactics. The specification of such systems is essential to the successful development of software projects. This paper proposes a goal-oriented requirements engineering approach for representing systems with cyber deception requirements, called iStar4Deception. The development of this approach followed the PRISE process to ensure conceptual rigor, compatibility with native iStar, and the reuse of well-established extensions documented in the iStar Extension Catalog and supported by piStar-EXT. To demonstrate the applicability of iStar4Deception, we conducted a real-world case study of a Brazilian bank slip payment system in which cyber deception mechanisms and automated redirection of malicious traffic are strategically deployed not only to detect, delay, and analyze attacks but also to preserve critical assets. The results show that the proposed extension enables a systematic modeling of deception-oriented goals, dependencies, and qualities, providing analysts with a structured approach to integrating cyber deception strategies into goal-oriented requirements models.Referências
Al-Sulaifanie, A., Biswas, S., and Al-Anbagi, I. (2024). A survey of network requirements for enabling effective cyber deception. IEEE Access, 12:31450–31472.
Ceron, J. M., Steding-Jessen, K., and Hoepers, C. (2013). Anatomia de abusos a servidores sip. In Anais do XIII Simpósio Brasileiro em Segurança da Informação e de Sistemas Computacionais (SBSeg), pages 44–57, Brasil. Sociedade Brasileira de Computação (SBC).
Climek, L. et al. (2016). Cyber deception in modern defense strategies. Journal of the Cyber Security & Information Systems Information Analysis Center, 4(1).
Cobalt Blog (2024). 11 biggest cybersecurity attacks in history. Online.
Dalpiaz, F., Franch, X., and Horkoff, J. (2016). istar 2.0: Language guide. Requirements Engineering.
de Faveri, C. (2021). Modeling Deception for Cyber Security. Phd thesis, NOVA University Lisbon, Lisbon.
Elahi, G., Yu, E., and Zannone, N. (2010). A vulnerability-centric requirements engineering framework: analyzing security attacks, countermeasures, and requirements based on vulnerabilities. Requirements Engineering, 15(1):41–62.
Franch, X., Maté, A., Trujillo, J. C., and Cares, C. (2018). On the joint use of i* with other modelling frameworks: A vision paper. In Proceedings of the 40th International Conference on Software Engineering: New Ideas and Emerging Results (ICSE-NIER), pages 33–36, Gothenburg, Sweden. ACM.
Giorgini, P., Rizzi, S., and Garzetti, M. (2005). Goal-oriented requirement analysis for data warehouse design. 8th ACM International Workshop on Data Warehousing and OLAP, pages 47–56.
Gonçalves, E. J. T., Castro, J., Araújo, J., and Heineck, T. (2018). A systematic literature review of istar extensions. Journal of Systems and Software, 137:1–33.
Gonçalves, E. J. T. (2019). PRISE: A Process to Support iStar Extensions. Doctoral thesis, Universidade Federal de Pernambuco, Recife, Brazil.
Han, X., Kheir, N., and Balzarotti, D. (2018). Deception techniques in computer security: A research perspective. ACM Computing Surveys (CSUR), 51(4):80:1–80:36.
Haseeb, J., Malik, S. u. R., Mansoori, M., and Welch, I. (2022). Probabilistic modelling of deception-based security framework using markov decision process. Computers & Security, 115:102599.
Horkoff, J. and Yu, E. (2016). Analyzing strategic actor relationships: A goal-oriented approach. Data & Knowledge Engineering.
ISO/IEC (2022). Information security, cybersecurity and privacy protection — information security management systems — requirements.
Kahlhofer, M. and Rass, S. (2024). Application layer cyber deception without developer interaction. In 2024 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW), pages 326–337. IEEE.
Kotenko, I., Fedorchenko, E., Novikova, E., and Jha, A. (2023). Cyber attacker profiling for risk analysis based on machine learning. Sensors, 23(4):2028.
Kotonya, G. and Sommerville, I. (1998). Requirements Engineering. John Wiley & Sons.
Lapouchnian, A. (2005). Goal-oriented requirements engineering: An overview of the research. Technical report, University of Toronto.
Liebowitz, D., Nepal, S., Moore, K., Christopher, C. J., Kanhere, S. S., Nguyen, D., Timmer, R. C., Longland, M., and Rathakumar, K. (2021). Deception for cyber defence: Challenges and opportunities. In 3rd IEEE International Conference on Trust, Privacy and Security in Intelligent Systems and Applications.
Mitnick, K. and Simon, W. L. (2002). The Art of Deception: Controlling the Human Element of Security. Wiley.
Morandini, M., Penserini, L., Perini, A., and Marchetto, A. (2017). Goal-oriented requirement analysis for data warehouse design. Requirement Engineering, pages 77–103.
Mouratidis, H., Giorgini, P., and Manson, G. (2007). Secure tropos: A security-oriented extension of the tropos methodology. International Journal of Software Engineering and Knowledge Engineering, 17.
Mylopoulos, J., Yu, E., Chung, L., and Nixon, B. (1999). Representing and using nonfunctional requirements: A process-oriented approach. IEEE Transactions on Software Engineering, 18(6):483–497.
Nagahama, F. Y., Farias, F., Aguiar, E., Gaspary, L., Granville, L., Cerqueira, E., and Abelém, A. (2012). Ipsflow – uma proposta de ips distribuído para captura e bloqueio seletivo de tráfego malicioso em redes definidas por software. In Anais do XII Simpósio Brasileiro em Segurança da Informação e de Sistemas Computacionais (SBSeg), pages 324–330, Brasil. Sociedade Brasileira de Computação (SBC).
NIST (1977). Guidelines for automatic data processing physical security and risk management. Technical report, National Bureau of Standards.
Pacheco, F. and Staino, D. (2025). Reinforcement of cyber deception strategies through simulated user behavior. In Proceedings of Cyber Deception Strategies. Springer.
Pirmez, M., Pirmez, L., da Costa Carmo, L. F. R., Delicato, F. C., Pires, P. F., and de Sousa, E. B. (2008). Prometheus: Um serviço de segurança adaptativa. In Anais do XXVI Simpósio Brasileiro de Redes de Computadores e Sistemas Distribuídos (SBRC 2008), pages 229–242, Porto Alegre, RS, Brasil. Sociedade Brasileira de Computação (SBC).
Ribeiro, M., Castro, J., and Pimentel, J. (2019). istar for safety-critical systems. In Proceedings of the 12th International i* Workshop, volume 2490 of CEUR Workshop Proceedings.
Samhruth, A., Girish, K., and Ganesh, N. (2025). Siren: Advancing cybersecurity through deception and adaptive analysis. In Arai, K., editor, Intelligent Computing, pages 506–519, Cham. Springer Nature.
Shinde, A., Doshi, P., and Setayeshfar, O. (2021). Cyber attack intent recognition and active deception using factored interactive POMDPs. In Proceedings of the 20th International Conference on Autonomous Agents and MultiAgent Systems (AAMAS ’21), pages 1200–1208, Richland, WA, USA. International Foundation for Autonomous Agents and Multiagent Systems (IFAAMAS).
Smith, D. L. (2005). Why We Lie: The Evolutionary Roots of Deception and the Unconscious Mind. Taylor & Francis.
Sommerville, I. (2011). Software Engineering. Pearson, 9 edition.
Spitzner, L. (2003). Honeypots: Tracking Hackers. Addison-Wesley.
Steingartner, W., Galinec, D., and Kozina, A. (2021). Threat defense: Cyber deception approach and education for resilience in hybrid threats model. Symmetry, 13(4).
van Lamsweerde, A. (2001). Goal-oriented requirements engineering: A guided tour. In Proceedings of the 5th IEEE International Symposium on Requirements Engineering, pages 249–262. IEEE.
Werneck, V. M. B., Oliveira, A. d. P. A., and Leite, J. C. S. d. P. (2009). Comparing gore frameworks: i-star and kaos. In 12th Workshop on Requirements Engineering.
Whaley, B. and Bell, J. A. (1991). Cheating and Deception. Transaction Publishers, New Brunswick.
Yu, E. (1995). Modelling Strategic Relationships for Process Reengineering. PhD thesis, University of Toronto.
Ceron, J. M., Steding-Jessen, K., and Hoepers, C. (2013). Anatomia de abusos a servidores sip. In Anais do XIII Simpósio Brasileiro em Segurança da Informação e de Sistemas Computacionais (SBSeg), pages 44–57, Brasil. Sociedade Brasileira de Computação (SBC).
Climek, L. et al. (2016). Cyber deception in modern defense strategies. Journal of the Cyber Security & Information Systems Information Analysis Center, 4(1).
Cobalt Blog (2024). 11 biggest cybersecurity attacks in history. Online.
Dalpiaz, F., Franch, X., and Horkoff, J. (2016). istar 2.0: Language guide. Requirements Engineering.
de Faveri, C. (2021). Modeling Deception for Cyber Security. Phd thesis, NOVA University Lisbon, Lisbon.
Elahi, G., Yu, E., and Zannone, N. (2010). A vulnerability-centric requirements engineering framework: analyzing security attacks, countermeasures, and requirements based on vulnerabilities. Requirements Engineering, 15(1):41–62.
Franch, X., Maté, A., Trujillo, J. C., and Cares, C. (2018). On the joint use of i* with other modelling frameworks: A vision paper. In Proceedings of the 40th International Conference on Software Engineering: New Ideas and Emerging Results (ICSE-NIER), pages 33–36, Gothenburg, Sweden. ACM.
Giorgini, P., Rizzi, S., and Garzetti, M. (2005). Goal-oriented requirement analysis for data warehouse design. 8th ACM International Workshop on Data Warehousing and OLAP, pages 47–56.
Gonçalves, E. J. T., Castro, J., Araújo, J., and Heineck, T. (2018). A systematic literature review of istar extensions. Journal of Systems and Software, 137:1–33.
Gonçalves, E. J. T. (2019). PRISE: A Process to Support iStar Extensions. Doctoral thesis, Universidade Federal de Pernambuco, Recife, Brazil.
Han, X., Kheir, N., and Balzarotti, D. (2018). Deception techniques in computer security: A research perspective. ACM Computing Surveys (CSUR), 51(4):80:1–80:36.
Haseeb, J., Malik, S. u. R., Mansoori, M., and Welch, I. (2022). Probabilistic modelling of deception-based security framework using markov decision process. Computers & Security, 115:102599.
Horkoff, J. and Yu, E. (2016). Analyzing strategic actor relationships: A goal-oriented approach. Data & Knowledge Engineering.
ISO/IEC (2022). Information security, cybersecurity and privacy protection — information security management systems — requirements.
Kahlhofer, M. and Rass, S. (2024). Application layer cyber deception without developer interaction. In 2024 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW), pages 326–337. IEEE.
Kotenko, I., Fedorchenko, E., Novikova, E., and Jha, A. (2023). Cyber attacker profiling for risk analysis based on machine learning. Sensors, 23(4):2028.
Kotonya, G. and Sommerville, I. (1998). Requirements Engineering. John Wiley & Sons.
Lapouchnian, A. (2005). Goal-oriented requirements engineering: An overview of the research. Technical report, University of Toronto.
Liebowitz, D., Nepal, S., Moore, K., Christopher, C. J., Kanhere, S. S., Nguyen, D., Timmer, R. C., Longland, M., and Rathakumar, K. (2021). Deception for cyber defence: Challenges and opportunities. In 3rd IEEE International Conference on Trust, Privacy and Security in Intelligent Systems and Applications.
Mitnick, K. and Simon, W. L. (2002). The Art of Deception: Controlling the Human Element of Security. Wiley.
Morandini, M., Penserini, L., Perini, A., and Marchetto, A. (2017). Goal-oriented requirement analysis for data warehouse design. Requirement Engineering, pages 77–103.
Mouratidis, H., Giorgini, P., and Manson, G. (2007). Secure tropos: A security-oriented extension of the tropos methodology. International Journal of Software Engineering and Knowledge Engineering, 17.
Mylopoulos, J., Yu, E., Chung, L., and Nixon, B. (1999). Representing and using nonfunctional requirements: A process-oriented approach. IEEE Transactions on Software Engineering, 18(6):483–497.
Nagahama, F. Y., Farias, F., Aguiar, E., Gaspary, L., Granville, L., Cerqueira, E., and Abelém, A. (2012). Ipsflow – uma proposta de ips distribuído para captura e bloqueio seletivo de tráfego malicioso em redes definidas por software. In Anais do XII Simpósio Brasileiro em Segurança da Informação e de Sistemas Computacionais (SBSeg), pages 324–330, Brasil. Sociedade Brasileira de Computação (SBC).
NIST (1977). Guidelines for automatic data processing physical security and risk management. Technical report, National Bureau of Standards.
Pacheco, F. and Staino, D. (2025). Reinforcement of cyber deception strategies through simulated user behavior. In Proceedings of Cyber Deception Strategies. Springer.
Pirmez, M., Pirmez, L., da Costa Carmo, L. F. R., Delicato, F. C., Pires, P. F., and de Sousa, E. B. (2008). Prometheus: Um serviço de segurança adaptativa. In Anais do XXVI Simpósio Brasileiro de Redes de Computadores e Sistemas Distribuídos (SBRC 2008), pages 229–242, Porto Alegre, RS, Brasil. Sociedade Brasileira de Computação (SBC).
Ribeiro, M., Castro, J., and Pimentel, J. (2019). istar for safety-critical systems. In Proceedings of the 12th International i* Workshop, volume 2490 of CEUR Workshop Proceedings.
Samhruth, A., Girish, K., and Ganesh, N. (2025). Siren: Advancing cybersecurity through deception and adaptive analysis. In Arai, K., editor, Intelligent Computing, pages 506–519, Cham. Springer Nature.
Shinde, A., Doshi, P., and Setayeshfar, O. (2021). Cyber attack intent recognition and active deception using factored interactive POMDPs. In Proceedings of the 20th International Conference on Autonomous Agents and MultiAgent Systems (AAMAS ’21), pages 1200–1208, Richland, WA, USA. International Foundation for Autonomous Agents and Multiagent Systems (IFAAMAS).
Smith, D. L. (2005). Why We Lie: The Evolutionary Roots of Deception and the Unconscious Mind. Taylor & Francis.
Sommerville, I. (2011). Software Engineering. Pearson, 9 edition.
Spitzner, L. (2003). Honeypots: Tracking Hackers. Addison-Wesley.
Steingartner, W., Galinec, D., and Kozina, A. (2021). Threat defense: Cyber deception approach and education for resilience in hybrid threats model. Symmetry, 13(4).
van Lamsweerde, A. (2001). Goal-oriented requirements engineering: A guided tour. In Proceedings of the 5th IEEE International Symposium on Requirements Engineering, pages 249–262. IEEE.
Werneck, V. M. B., Oliveira, A. d. P. A., and Leite, J. C. S. d. P. (2009). Comparing gore frameworks: i-star and kaos. In 12th Workshop on Requirements Engineering.
Whaley, B. and Bell, J. A. (1991). Cheating and Deception. Transaction Publishers, New Brunswick.
Yu, E. (1995). Modelling Strategic Relationships for Process Reengineering. PhD thesis, University of Toronto.
Publicado
01/09/2026
Como Citar
CELESTINO, Ricardo Antônio Rebouças; CARVALHO, Jhonatan de Sousa; GONÇALVES, Enyo; MAIA, Paulo Henrique Mendes.
Specifying Deception Requirements with iStar. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ.
Anais [...].
Porto Alegre: Sociedade Brasileira de Computação,
2026
.
p. 1073-1088.
DOI: https://doi.org/10.5753/sbseg.2026.26919.
