首页> 外文会议>IEEE International Symposium on Software Reliability Engineering Workshops >SIDE: Security-aware Integrated Development Environment
【24h】

SIDE: Security-aware Integrated Development Environment

机译:方:安全感知的集成开发环境

获取原文

摘要

An effective way for building secure software is to embed security into software in the early stages of software development. Thus, we aim to study several evidences of code anomalies introduced during the software development phase, that may be indicators of security issues in software, such as code smells, structural complexity represented by diverse software metrics, the issues detected by static code analysers, and finally missing security best practices. To use such evidences for vulnerability prediction and removal, we first need to understand how they are correlated with security issues. Then, we need to discover how these imperfect raw data can be integrated to achieve a reliable, accurate and valuable decision about a portion of code. Finally, we need to construct a security actuator providing suggestions to the developers to remove or fix the detected issues from the code. All of these will lead to the construction of a framework, including security monitoring, security analyzer, and security actuator platforms, that are necessary for a security-aware integrated development environment (SIDE).
机译:为构建安全软件的一个有效方法是嵌入到安全软件在软件开发的早期阶段。因此,我们的目标是研究在软件开发阶段引入代码异常几个证据,这可能是在软件的安全性问题的指标,如代码味道,结构由不同的软件度量为代表的复杂性,这些问题通过静态代码分析仪检测,最后缺少的安全最佳实践。使用这种证据的脆弱性预测和清除,我们首先需要了解他们如何与安全问题相关。然后,我们需要发现这些不完美的原始数据如何被集成,实现有关的代码部分的可靠,准确,有价值的决策。最后,我们需要构建一个安全执行机构提供建议,向开发人员从代码中删除或修复检测到的问题。所有这些都将导致一个框架的建设,包括安全监控,安全分析,安全性和执行器的平台,这是必要的安全意识的集成开发环境(SIDE)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号