首页> 外文会议>Engineering secure software and systems >Protection Poker: Structuring Software Security Risk Assessment and Knowledge Transfer
【24h】

Protection Poker: Structuring Software Security Risk Assessment and Knowledge Transfer

机译:保护扑克:构建软件安全风险评估和知识转移

获取原文
获取原文并翻译 | 示例

摘要

Discovery of security vulnerabilities is on the rise. As a result, software development teams must place a higher priority on preventing the injection of vulnerabilities in software as it is developed. Because the focus on software security has increased only recently, software development teams often do not have expertise in techniques for identifying security risk, understanding the impact of a vulnerability, or knowing the best mitigation strategy. We propose the Protection Poker activity as a collaborative and informal form of misuse case development and threat modeling that plays off the diversity of knowledge and perspective of the participants. An excellent outcome of Protection Poker is that security knowledge passed around the team. Students in an advanced undergraduate software engineering course at North Carolina State University participated in a Protection Poker session conducted as a laboratory exercise. Students actively shared misuse cases, threat models, and their limited software security expertise as they discussed vulnerabilities in their course project. We observed students relating vulnerabilities to the business impacts of the system. Protection Poker lead to a more effective software security learning experience than in prior semesters. A pilot of the use of Protection Poker with an industrial partner began in October 2008. The first security discussion structured via Protection Poker caused two requirements to be revised for added security fortification; led to the immediate identification of one vulnerability in the system; initiated a meeting on the prioritization of security defects; and instigated a call for an education session on preventing cross site scripting vulnerabilities.
机译:正在发现安全漏洞。因此,软件开发团队必须在防止软件开发过程中注入漏洞方面获得更高的优先级。因为对软件安全的关注只是最近才增加的,所以软件开发团队通常不具备识别安全风险,了解漏洞影响或了解最佳缓解策略的技术专长。我们建议保护扑克活动是一种滥用形式的案例开发和威胁建模的协作和非正式形式,可以消除参与者的知识和观点的多样性。保护扑克的一项出色成果是,安全知识在团队中传递。北卡罗莱纳州立大学的高级本科软件工程课程的学生参加了作为实验练习的保护扑克课程。在讨论课程项目中的漏洞时,学生们积极分享滥用案例,威胁模型和有限的软件安全专业知识。我们观察到学生将漏洞与系统的业务影响相关联。与以前的学期相比,Protection Poker带来了更有效的软件安全学习经验。从2008年10月开始,与一个工业伙伴一起使用保护扑克的试验。通过保护扑克进行的首次安全讨论导致对两项要求进行了修订,以增加安全性。导致立即识别系统中的一个漏洞;发起了关于安全缺陷优先级的会议;并发起了关于防止跨站点脚本漏洞的培训会议。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号