首页> 外文会议>2018 IEEE 23rd Pacific Rim International Symposium on Dependable Computing >An Approach for Trustworthiness Benchmarking Using Software Metrics
【24h】

An Approach for Trustworthiness Benchmarking Using Software Metrics

机译:一种使用软件指标进行可信度基准测试的方法

获取原文
获取原文并翻译 | 示例

摘要

Trustworthiness is a paramount concern for users and customers in the selection of a software solution, specially in the context of complex and dynamic environments, such as Cloud and IoT. However, assessing and benchmarking trustworthiness (worthiness of software for being trusted) is a challenging task, mainly due to the variety of application scenarios (e.g., businesscritical, safety-critical), the large number of determinative quality attributes (e.g., security, performance), and last, but foremost, due to the subjective notion of trust and trustworthiness. In this paper, we present trustworthiness as a measurable notion in relative terms based on security attributes and propose an approach for the assessment and benchmarking of software. The main goal is to build a trustworthiness assessment model based on software metrics (e.g., Cyclomatic Complexity, CountLine, CBO) that can be used as indicators of software security. To demonstrate the proposed approach, we assessed and ranked several files and functions of the Mozilla Firefox project based on their trustworthiness score and conducted a survey among several software security experts in order to validate the obtained rank. Results show that our approach is able to provide a sound ranking of the benchmarked software.
机译:对于用户和客户而言,在选择软件解决方案时,尤其是在复杂而动态的环境(例如云​​和物联网)的环境中,可信赖性是至关重要的。但是,评估和对可信赖性(值得信赖的软件的价值)进行基准测试是一项具有挑战性的任务,这主要是由于各种应用场景(例如,业务关键型,安全关键型),大量确定性质量属性(例如,安全性,性能) ),最后也是最重要的一点,这要归功于信任和信任的主观观念。在本文中,我们将可信赖性作为一种基于安全属性的相对术语可度量的概念,并提出了一种评估和基准测试软件的方法。主要目标是基于软件指标(例如,Cyclomatic Complexity,CountLine,CBO)建立可信赖性评估模型,该模型可用作软件安全性的指标。为了演示所提出的方法,我们根据Mozilla Firefox项目的可信赖度评分对它们的几个文件和功能进行了评估和排名,并在几位软件安全专家之间进行了调查,以验证所获得的排名。结果表明,我们的方法能够为基准测试软件提供良好的排名。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号