Automating risk analysis of software design models.

The growth of the internet and networked systems has exposed software to an increased amount of security threats. One of the responses from software developers to these threats is the introduction of security activities in the software development lifecycle. This paper describes an approach to reduc...

Descripción completa

Detalles Bibliográficos
Publicado en:Scientific World Journal pp. 805856 - 805857
Autores principales: Frydman, Maxime, Ruiz, Guifré, Heymann, Elisa, César, Eduardo, Miller, Barton P
Formato: research Journal Article
Publicado: Wiley-Blackwell 2014
Acceso en línea:Ver este registro en EBSCOhost
fields @attributes:
  recordID: 1
pdfLink:
plink: https://search.ebscohost.com/login.aspx?direct=true&db=ccm&AN=103841144&site=ehost-live
header:
  @attributes:
    shortDbName: ccm
    uiTerm: 103841144
    longDbName: CINAHL Complete
    uiTag: AN
  controlInfo:
    bkinfo:
    dissinfo:
    jinfo:
      jid:
        1537744X
        1BX5
      jtl: Scientific World Journal
      issn: 1537744X
      maglogo: N
    pubinfo:
      dt: 2014
      pid: 480
      pub: Wiley-Blackwell
      place: Malden, Massachusetts
    artinfo:
      ui:
        103841144
        103841144
        NLM25136688
        2012689890
        10.1155/2014/805856
        NLM25136688
        PMC4090456
        103841144
      ppf: 805856
      ppct: 1
      formats:
      tig:
        atl: Automating risk analysis of software design models.
      aug:
        au:
          Frydman, Maxime
          Ruiz, Guifré
          Heymann, Elisa
          César, Eduardo
          Miller, Barton P
        affil: Computer Architecture and Operating Systems Department, Universitat Autónoma de Barcelona, Campus UAB, Edifici Q, Bellaterra, 08193 Barcelona, Spain.
      sug:
        subj:
          Data Security
          Models, Theoretical
          Risk Assessment
          Software Design
      ab: The growth of the internet and networked systems has exposed software to an increased amount of security threats. One of the responses from software developers to these threats is the introduction of security activities in the software development lifecycle. This paper describes an approach to reduce the need for costly human expertise to perform risk analysis in software, which is common in secure development methodologies, by automating threat modeling. Reducing the dependency on security experts aims at reducing the cost of secure development by allowing non-security-aware developers to apply secure development with little to no additional cost, making secure development more accessible. To automate threat modeling two data structures are introduced, identification trees and mitigation trees, to identify threats in software designs and advise mitigation techniques, while taking into account specification requirements and cost concerns. These are the components of our model for automated threat modeling, AutSEC. We validated AutSEC by implementing it in a tool based on data flow diagrams, from the Microsoft security development methodology, and applying it to VOMS, a grid middleware component, to evaluate our model's performance.
      pubtype: Academic Journal
      doctype:
        research
        Journal Article
      ougenre: Article
    language: English
    refInfo:
    holdings:
      @attributes:
        islocal: N