Automating risk analysis of software design models.
The growth of the internet and networked systems has exposed software to an increased amount of security threats. One of the responses from software developers to these threats is the introduction of security activities in the software development lifecycle. This paper describes an approach to reduc...
| Publicado en: | Scientific World Journal pp. 805856 - 805857 |
|---|---|
| Autores principales: | , , , , |
| Formato: | research Journal Article |
| Publicado: |
Wiley-Blackwell
2014
|
| Acceso en línea: | Ver este registro en EBSCOhost |
| fields | @attributes: recordID: 1 pdfLink: plink: https://search.ebscohost.com/login.aspx?direct=true&db=ccm&AN=103841144&site=ehost-live header: @attributes: shortDbName: ccm uiTerm: 103841144 longDbName: CINAHL Complete uiTag: AN controlInfo: bkinfo: dissinfo: jinfo: jid: 1537744X 1BX5 jtl: Scientific World Journal issn: 1537744X maglogo: N pubinfo: dt: 2014 pid: 480 pub: Wiley-Blackwell place: Malden, Massachusetts artinfo: ui: 103841144 103841144 NLM25136688 2012689890 10.1155/2014/805856 NLM25136688 PMC4090456 103841144 ppf: 805856 ppct: 1 formats: tig: atl: Automating risk analysis of software design models. aug: au: Frydman, Maxime Ruiz, Guifré Heymann, Elisa César, Eduardo Miller, Barton P affil: Computer Architecture and Operating Systems Department, Universitat Autónoma de Barcelona, Campus UAB, Edifici Q, Bellaterra, 08193 Barcelona, Spain. sug: subj: Data Security Models, Theoretical Risk Assessment Software Design ab: The growth of the internet and networked systems has exposed software to an increased amount of security threats. One of the responses from software developers to these threats is the introduction of security activities in the software development lifecycle. This paper describes an approach to reduce the need for costly human expertise to perform risk analysis in software, which is common in secure development methodologies, by automating threat modeling. Reducing the dependency on security experts aims at reducing the cost of secure development by allowing non-security-aware developers to apply secure development with little to no additional cost, making secure development more accessible. To automate threat modeling two data structures are introduced, identification trees and mitigation trees, to identify threats in software designs and advise mitigation techniques, while taking into account specification requirements and cost concerns. These are the components of our model for automated threat modeling, AutSEC. We validated AutSEC by implementing it in a tool based on data flow diagrams, from the Microsoft security development methodology, and applying it to VOMS, a grid middleware component, to evaluate our model's performance. pubtype: Academic Journal doctype: research Journal Article ougenre: Article language: English refInfo: holdings: @attributes: islocal: N |
|---|