首页> 外文会议>International Conference on Availability, Reliability and Security >A Novel Security-Enhanced Agile Software Development Process Applied in an Industrial Setting
【24h】

A Novel Security-Enhanced Agile Software Development Process Applied in an Industrial Setting

机译:在工业环境中应用了一种新的安全增强敏捷软件开发过程

获取原文

摘要

A security-enhanced agile software development process, SEAP, is introduced in the development of a mobile money transfer system at Ericsson Corp. A specific characteristic of SEAP is that it includes a security group consisting of four different competences, i.e., Security manager, security architect, security master and penetration tester. Another significant feature of SEAP is an integrated risk analysis process. In analyzing risks in the development of the mobile money transfer system, a general finding was that SEAP either solves risks that were previously postponed or solves a larger proportion of the risks in a timely manner. The previous software development process, i.e., The baseline process of the comparison outlined in this paper, required 2.7 employee hours spent for every risk identified in the analysis process compared to, on the average, 1.5 hours for the SEAP. The baseline development process left 50% of the risks unattended in the software version being developed, while SEAP reduced that figure to 22%. Furthermore, SEAP increased the proportion of risks that were corrected from 12.5% to 67.1%, i.e., More than a five times increment. This is important, since an early correction may avoid severe attacks in the future. The security competence in SEAP accounts for 5% of the personnel cost in the mobile money transfer system project. As a comparison, the corresponding figure, i.e., For security, was 1% in the previous development process.
机译:安全性增强的敏捷软件开发过程中,SEAP,在SEAP爱立信公司的具体特性的移动转账系统的开发介绍的是,它包括由四个不同权限的安全组,即,安全经理,安全建筑师,安老爷和渗透测试。 SEAP的另一个显著特点是综合风险分析过程。在移动转账系统的发展分析风险,一般的发现是,先前推迟或解决了风险及时比重较大或者SEAP解决了风险。以前的软件开发过程,即,在本文中介绍的比较的基准过程,需要花费在分析过程中识别相比,每一个风险2.7员工小时,平均1.5小时的SEAP。基线发展过程中遗留的无人看管的软件版本正在开发中的风险50%,同时减少SEAP这一数字到22%。此外,SEAP增加了从12.5%校正至67.1%的风险,即比例,超过五次增量。这一点很重要,因为早期的修正可能在将来避免严重的攻击。在SEAP安全能力占移动汇款系统,工程造价人员的5%。作为比较,在相应的数字,即,为了安全起见,在以前开发过程1%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号