An integrated security testing framework for Secure Software Development Life Cycle

被引:0
|
作者
Tung, Yuan-Hsin [1 ]
Lo, Sheng-Chen [1 ]
Shih, Jen-Feng [1 ]
Lin, Hung-Fu [1 ]
机构
[1] Chunghwa Telecom Co Ltd, Telecommun Lab, Taipei, Taiwan
关键词
SSDLC; security testing tool; vulnerability analysis; integrated framework;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Hundreds of vulnerabilities and security defects are disclosed by hackers, developers, and users. The better way to improve software security is to enhance security process into SDLC processes. To keep software secure, security enhancement of the SDLC process involves lots of practices and activities to achieve goal of security. However, how to adopt these activities well to improve software security is an important problem. In this paper, we propose an integrated security testing framework for secure software development life cycle. In our proposed framework, we apply security activities and practices of SSDLC to generate security guidelines. Furthermore, we integrate security testing tools as a platform to provide testing service and converge testing results of tools to improve accurate of test. To evaluate our proposed framework, we construct the prototype system by referring phases of framework. Our system can integrate various security testing tools and support secure activities in each phase of SSDLC. We had applied our system to at least 50 software developing projects. The results indicate that our prototype system can provide quality and stable service.
引用
收藏
页数:4
相关论文
共 50 条
  • [1] A Review and Catalog of Security Metric during the Secure Software Development Life Cycle
    Sampada, G. C.
    Sake, Tende Ivo
    Prasad, Amrita
    [J]. RECENT ADVANCES IN ELECTRICAL & ELECTRONIC ENGINEERING, 2021, 14 (04) : 398 - 405
  • [2] Secure Software Development Model: A Guide for Secure Software Life Cycle
    Daud, Malik Imran
    [J]. INTERNATIONAL MULTICONFERENCE OF ENGINEERS AND COMPUTER SCIENTISTS (IMECS 2010), VOLS I-III, 2010, : 724 - 728
  • [3] Software Development Life Cycle Security Issues
    Kaur, Daljit
    Kaur, Parminder
    [J]. 2ND INTERNATIONAL CONFERENCE ON METHODS AND MODELS IN SCIENCE AND TECHNOLOGY (ICM2ST-11), 2011, 1414
  • [4] Towards Incorporation of Software Security Testing Framework in Software Development
    Hassan, Nor Hafeizah
    Selamat, Siti Rahayu
    Sahib, Shahrin
    Hussin, Burairah
    [J]. SOFTWARE ENGINEERING AND COMPUTER SYSTEMS, PT 1, 2011, 179 : 16 - 30
  • [5] Better Left Shift Security! Framework for Secure Software Development
    Dawoud, Abdallah
    Finster, Soeren
    Coppik, Nicolas
    Ashiwal, Virendra
    [J]. 9TH IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS, EUROS&PW 2024, 2024, : 642 - 649
  • [6] Embedding Security in Software Development Life Cycle (SDLC)
    Khari, Manju
    Vaishali
    Kumar, Prabhat
    [J]. PROCEEDINGS OF THE 10TH INDIACOM - 2016 3RD INTERNATIONAL CONFERENCE ON COMPUTING FOR SUSTAINABLE GLOBAL DEVELOPMENT, 2016, : 2182 - 2186
  • [7] Reframing Security in Contemporary Software Development Life Cycle
    Frijns, Pieter
    Bierwolf, Robert
    Zijderhand, Tom
    [J]. 2018 IEEE INTERNATIONAL CONFERENCE ON TECHNOLOGY MANAGEMENT, OPERATIONS AND DECISIONS (ICTMOD), 2018, : 230 - 236
  • [8] Evaluation of engineering approaches in the secure software development life cycle
    Busch, Marianne
    Koch, Nora
    Wirsing, Martin
    [J]. Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2014, 8431 : 234 - 265
  • [9] Evaluation of engineering approaches in the secure software development life cycle
    Busch, Marianne
    Koch, Nora
    Wirsing, Martin
    [J]. Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2014, 8431 : 234 - 265
  • [10] Evaluation of engineering approaches in the secure software development life cycle
    Busch, Marianne
    Koch, Nora
    Wirsing, Martin
    [J]. 1600, Springer Verlag (8431): : 234 - 265