Measuring software security from the design of software

Marko Saarela, Shohreh Hosseinzadeh, Sami Hyrynsalmi, Ville Leppänen

    Tutkimustuotos: KonferenssiartikkeliTieteellinenvertaisarvioitu

    3 Sitaatiot (Scopus)

    Abstrakti

    With the increasing use of mobile phones in contemporary society, more and more networked computers are connected to each other. This has brought along security issues. To solve these issues, both research and development communities are trying to build more secure software. However, there is the question that how the secure software is defined and how the security could be measured. In this paper, we study this problem by studying what kinds of security measurement tools (i.e. metrics) are available, and what these tools and metrics reveal about the security of software. As the result of the study, we noticed that security verification activities fall into two main categories, evaluation and assurance. There exist 34 metrics for measuring the security, from which 29 are assurance metrics and 5 are evaluation metrics. Evaluating and studying these metrics, lead us to the conclusion that the general quality of the security metrics are not in a satisfying level that could be suitably used in daily engineering work flows. They have both theoretical and practical issues that require further research, and need to be improved.
    AlkuperäiskieliEnglanti
    OtsikkoProceedings of the 18th International Conference on Computer Systems and Technologies
    ToimittajatBoris Rachev, Angel Smrikarov
    KustantajaACM
    Sivut179-186
    ISBN (painettu)978-1-4503-5234-5
    DOI - pysyväislinkit
    TilaJulkaistu - 22 kesäk. 2017
    OKM-julkaisutyyppiA4 Artikkeli konferenssijulkaisussa
    TapahtumaINTERNATIONAL CONFERENCE ON COMPUTER SYSTEMS AND TECHNOLOGIES -
    Kesto: 1 tammik. 1900 → …

    Conference

    ConferenceINTERNATIONAL CONFERENCE ON COMPUTER SYSTEMS AND TECHNOLOGIES
    Ajanjakso1/01/00 → …

    Julkaisufoorumi-taso

    • Jufo-taso 1

    Sormenjälki

    Sukella tutkimusaiheisiin 'Measuring software security from the design of software'. Ne muodostavat yhdessä ainutlaatuisen sormenjäljen.

    Siteeraa tätä