首页> 外文会议>Requirements engineering: Foundation for software quality >Supporting Requirements Engineers in Recognising Security Issues
【24h】

Supporting Requirements Engineers in Recognising Security Issues

机译:支持需求工程师识别安全问题

获取原文
获取原文并翻译 | 示例

摘要

Context & motivation: More and more software projects today are security-related in one way or the other. Many environments are initially not considered security-related and no security experts are assigned. Requirements engineers often fail to recognise indicators for security problems. Question/problem: Ignoring security issues early in a project is a major source of recurring security problems in practice. Identifying security-relevant requirements is labour-intensive and error-prone. Security may be neglected in order to finish on time and in budget. Principal ideas/results: In this paper, we address this problem by presenting a tool-supported method that provides assistance for requirements engineering, with an emphasis on security requirements. We investigate whether security-relevant requirements can be automatically identified using a Bayesian classifier. Our results indicate that this is feasible, in particular if the classifier is trained with domain specific data and documents from previous projects. Contribution: We show how the ability to identify security-relevant requirements can be integrated in a workflow of requirements analysis and reuse of experience. In practice, this can increase security awareness within the software development process. WE- discuss limitations and potential of this approach.
机译:背景和动机:当今越来越多的软件项目以某种方式与安全性相关。最初,许多环境不被视为与安全性相关,并且没有指派安全专家。需求工程师常常无法识别安全问题的指标。问题:在项目早期就忽略安全问题是实践中反复出现的安全问题的主要来源。识别与安全性相关的需求是劳动密集型且容易出错的。为了按时按预算完成工作,可能会忽略安全性。主要思想/结果:在本文中,我们通过提出一种工具支持的方法来解决此问题,该方法可为需求工程提供帮助,重点是安全性需求。我们调查是否可以使用贝叶斯分类器自动识别与安全相关的要求。我们的结果表明,这是可行的,特别是如果使用领域特定的数据和先前项目中的文档训练分类器。贡献:我们展示了如何将与安全相关的需求识别功能集成到需求分析和经验重用的工作流程中。实际上,这可以提高软件开发过程中的安全意识。我们讨论了这种方法的局限性和潜力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号