首页> 外文期刊>The international arab journal of information technology >Performance Analysis of Security Requirements Engineering Framework by Measuring the Vulnerabilities
【24h】

Performance Analysis of Security Requirements Engineering Framework by Measuring the Vulnerabilities

机译:通过测量漏洞对安全需求工程框架进行性能分析

获取原文
获取原文并翻译 | 示例
           

摘要

To develop security critical web applications, specifying security requirements is important, since 75% to 80% of all attacks happen at the web application layer. We adopted security requirements engineering methods to identify security requirements at the early stages of software development life cycle so as to minimize vulnerabilities at the later phases. In this paper, we present the evaluation of Model Oriented Security Requirements Engineering (MOSRE) framework and Security Requirements Engineering Framework (SREF) by implementing the identified security requirements of a web application through each framework while developing respective web application. We also developed a web application without using any of the security requirements engineering method in order to prove the importance of security requirements engineering phase in software development life cycle. The developed web applications were scanned for vulnerabilities using the web application scanning tool. The evaluation was done in two phases of software development life cycle: requirements engineering and testing. From the results, we observed that the number of vulnerabilities detected in the web application developed by adopting MOSRE framework is less, when compared to the web applications developed adopting SREF and without using any security requirements engineering method. Thus, this study led the requirements engineers to use MOSRE framework to elicit security requirements efficiently and also trace security requirements from requirements engineering phase to later phases of software development life cycle for developing secure web applications.
机译:对于开发安全性至关重要的Web应用程序,指定安全性要求很重要,因为所有攻击的75%至80%发生在Web应用程序层。我们采用了安全需求工程方法来在软件开发生命周期的早期阶段确定安全需求,以最大程度地减少后期阶段的漏洞。在本文中,我们通过开发每个Web应用程序时通过每个框架实现已确定的Web应用程序安全要求,来介绍面向模型的安全需求工程(MOSRE)框架和安全需求工程框架(SREF)的评估。我们还开发了一个不使用任何安全需求工程方法的Web应用程序,以证明安全需求工程阶段在软件开发生命周期中的重要性。使用Web应用程序扫描工具对开发的Web应用程序进行了漏洞扫描。评估是在软件开发生命周期的两个阶段完成的:需求工程和测试。从结果中,我们发现,与采用SREF且未使用任何安全性需求工程方法开发的Web应用程序相比,采用MOSRE框架开发的Web应用程序中检测到的漏洞数量较少。因此,这项研究导致需求工程师使用MOSRE框架来有效地得出安全需求,并且还跟踪从需求工程阶段到软件开发生命周期的后续阶段的安全需求,以开发安全的Web应用程序。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号