...
首页> 外文期刊>Requirements Engineering >A descriptive study of Microsoft's threat modeling technique
【24h】

A descriptive study of Microsoft's threat modeling technique

机译:微软威胁建模技术的描述性研究

获取原文
获取原文并翻译 | 示例

摘要

Microsoft's STRIDE is a popular threat modeling technique commonly used to discover the security weaknesses of a software system. In turn, discovered weaknesses are a major driver for incepting security requirements. Despite its successful adoption, to date no empirical study has been carried out to quantify the cost and effectiveness of STRIDE. The contribution of this paper is the evaluation of STRIDE via a descriptive study that involved 57 students in their last master year in computer science. The study addresses three research questions. First, it assesses how many valid threats per hour are produced on average. Second, it evaluates the correctness of the analysis results by looking at the average number of false positives, i.e., the incorrect threats. Finally, it determines the completeness of the analysis results by looking at the average number of false negatives, i.e., the overlooked threats.
机译:微软的STRIDE是一种流行的威胁建模技术,通常用于发现软件系统的安全漏洞。反过来,发现的弱点是接受安全要求的主要驱动力。尽管已成功采用STRIDE,但迄今为止尚未进行任何经验研究来量化STRIDE的成本和有效性。本文的贡献是通过一项描述性研究对STRIDE进行了评估,该研究涉及计算机科学专业上一学年的57名学生。该研究解决了三个研究问题。首先,它评估平均每小时产生多少有效威胁。其次,它通过查看误报的平均数量(即不正确的威胁)来评估分析结果的正确性。最后,它通过查看误报的平均数量(即被忽略的威胁)来确定分析结果的完整性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号