首页> 外文会议>European conference on software architecture >Two Architectural Threat Analysis Techniques Compared
【24h】

Two Architectural Threat Analysis Techniques Compared

机译:两种架构威胁分析技术的比较

获取原文

摘要

In an initial attempt to systematize the research field of architectural threat analysis, this paper presents a comparative study of two threat analysis techniques. In particular, the controlled experiment presented here compares two variants of Microsoft's STRIDE. The two variants differ in the way the analysis is performed. In one case, each component of the software system is considered in isolation and scrutinized for potential security threats. In the other case, the analysis has a wider scope and considers the security threats that might occur in a pair of interacting software components. The study compares the techniques with respect to their effectiveness in finding security threats (benefits) as well as the time that it takes to perform the analysis (cost). We also look into other human aspects which are important for industrial adoption, like, for instance, the perceived difficulty in learning and applying the techniques as well as the overall preference of our experimental participants.
机译:在系统化体系结构威胁分析研究领域的初步尝试中,本文对两种威胁分析技术进行了比较研究。特别是,此处介绍的受控实验比较了Microsoft的STRIDE的两个变体。两种变体在执行分析的方式上有所不同。在一种情况下,软件系统的每个组件都被单独考虑并仔细检查是否存在潜在的安全威胁。在另一种情况下,分析的范围更广,并考虑了可能在一对交互的软件组件中发生的安全威胁。该研究对这些技术在发现安全威胁(收益)的有效性以及执行分析所需的时间(成本)方面进行了比较。我们还研究了其他对工业采用至关重要的人的方面,例如,在学习和应用技术方面的感知困难以及实验参与者的总体偏爱。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号