首页> 外文期刊>Arabian Journal for Science and Engineering >A Systematic Review and Analytical Evaluation of Security Requirements Engineering Approaches
【24h】

A Systematic Review and Analytical Evaluation of Security Requirements Engineering Approaches

机译:安全需求工程方法的系统回顾和分析评估

获取原文
获取原文并翻译 | 示例
       

摘要

Security is an inevitable concern in today's scenario of software-based application's pervasiveness and development practices. Researchers and practitioners frequently advocate that security-related aspects should be integrated and incorporated right from the beginning of SDLC. Security requirements engineering (SRE) plays an important role during the inceptive phases of software development. Thereby, we conducted a systematic review of the current state of the literature related to SRE. In total, we selected and analyzed 108 relevant studies. After analyzing the selected studies, we identified 20 different SRE approaches and compared them on different technical parameters like 'performance in the requirements subphase,' 'usability with respect to size and complexity of the project,' 'notation used,' 'industry recognition/adoption,' 'tool support,' 'standards integration' and 'elicitation technique used.' The results of this study are based on the comparative analysis of the SRE approaches, their analytical evaluation by the authors and trends observed during the course of the review. The major findings of this study indicate that SRE approaches like 'Misuse case, Secure Tropos, SEPP and SQUARE' are most popular among researchers while UML-based approaches like 'Misuse Case, SecureUML and UMLsec' are easily adaptable approaches. Threat modeling as an activity is adapted by most of the SRE approaches while few approaches support risk analysis. In addition, among several other findings, our study indicates that most of the SRE approaches fail to integrate security standards and formal methods. The contribution of this work is consequently that of supplying researchers with a summarized comparison of existing SRE approaches, along with the best practices adopted in the field of security requirements engineering. The insights provided here on selection appropriateness may prove to be instrumental for research in the area and may significantly facilitate both researchers and practitioners.
机译:在当今基于软件的应用程序无处不在和开发实践中,安全性是不可避免的问题。研究人员和从业人员经常主张,从SDLC开始就应将与安全相关的方面进行整合和整合。安全需求工程(SRE)在软件开发的初始阶段起着重要作用。因此,我们对与SRE相关的文献进行了系统回顾。我们总共选择并分析了108篇相关研究。在对选定的研究进行分析之后,我们确定了20种不同的SRE方法,并将它们与不同的技术参数进行了比较,例如“需求子阶段的性能”,“项目规模和复杂性的可用性”,“使用的注释”,“行业认可/采用”,“工具支持”,“标准集成”和“启发式技术”。这项研究的结果基于对SRE方法的比较分析,作者对它们的分析评估以及在审阅过程中观察到的趋势。这项研究的主要发现表明,诸如“滥用案例,Secure Tropos,SEPP和SQUARE”之类的SRE方法在研究人员中最为流行,而诸如“滥用案例,SecureUML和UMLsec”之类基于UML的方法则很容易适应。威胁建模作为一种活动可以通过大多数SRE方法进行调整,而很少有方法可以支持风险分析。此外,除其他几个发现外,我们的研究还表明,大多数SRE方法都无法集成安全标准和正式方法。因此,这项工作的贡献在于为研究人员提供了对现有SRE方法以及安全需求工程领域采用的最佳实践的汇总比较。此处提供的关于选择适当性的见解可能被证明对该领域的研究有用,并且可以极大地促进研究人员和从业人员的工作。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号