首页> 外文会议>IEEE Conference on Application, Information and Network Security >A Review of Factors Influencing the Implementation of Secure Framework for in-House Web Application Development in Malaysian Public Sector
【24h】

A Review of Factors Influencing the Implementation of Secure Framework for in-House Web Application Development in Malaysian Public Sector

机译:影响马来西亚公共部门内部网络应用开发安全框架实施的因素述评

获取原文

摘要

Every year, web applications have expanded their presence in more areas in financial organizations, health organizations, public sector, retail and accommodation. Security is important in data protection so as not to be infringed by unauthorized parties. If the vulnerabilities found are not amended, it leads to cyber-attacks such as Structured Query Language Injection Attack (SQLIA) performed by certain parties which enable them to gain unauthorized data access. To cater security issues, variety of security frameworks for secure software development life cycle (SDLC) were introduced. Secure SDLC is created by integrating security-related activities to an each phase of in used development methodologies such as waterfall model or agile model. However, the application security problem continues to grow. Strict, complicated and heavyweight frameworks are underutilized due to several factors. The factors that influence the implementation of secure SDLC identified in public sector (the scope is State Secretary Offices in Malaysia) are inadequate development timeline, improper development team size and less awareness of team members' workload. It is agreed that integrating security at earlier (requirement and design) phase is the most effective and cheapest way to develop secure web application. Hence, an adaptive secure SDLC model is proposed to integrate security activities using Fuzzy Analytic Hierarchy Process (FAHP) focusing on the influence factors as the main criteria and meet the international and local secure frameworks standards. The proposed model will recommend adaptive security activities as a guideline to be applied at earlier phases of SDLC to help eliminate/ minimize the web application vulnerabilities and increase the application security and implemented as a proof-of-concept prototype at selected Malaysian public sector for in-house web application development.
机译:每年,Web应用程序在金融组织,卫生组织,公共部门,零售和住宿的更多领域扩大了业务。安全性在数据保护中非常重要,以免被未经授权的派对侵犯。如果未修改发现的漏洞,它会导致网络攻击,例如由某些方面执行的结构化查询语言注入攻击(SQLIA),使其能够获得未经授权的数据访问。为了迎合安全问题,介绍了安全软件开发生命周期(SDLC)的各种安全框架。通过将安全相关的活动集成到瀑布模型或敏捷模型等二手开发方法中的每个阶段来创建安全SDLC。但是,应用安全问题继续增长。由于几个因素,严格,复杂和重量级框架未充分利用。影响公共部门中确定的安全SDLC实施的因素(范围是马来西亚州秘书处)是发展时间表不足,发展团队规模不当和对团队成员工作量不太了解。同意在早期(要求和设计)阶段集成安全性是开发安全Web应用程序的最有效和最便宜的方式。因此,提出了一种自适应安全SDLC模型,用于使用模糊分析层次处理(FAHP)集成安全活动,这些过程专注于影响因素作为主要标准,符合国际和本地安全框架标准。拟议的模型将推荐自适应安全活动作为在SDLC的早期阶段应用的指导,以帮助消除/最小化Web应用程序漏洞,并增加应用程序安全性,并在选定的马来西亚公共部门作为概念验证原型实施。 -House Web应用程序开发。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号