An integrated security testing framework for Secure Software Development Life Cycle

被引:0
|
作者
Tung, Yuan-Hsin [1 ]
Lo, Sheng-Chen [1 ]
Shih, Jen-Feng [1 ]
Lin, Hung-Fu [1 ]
机构
[1] Chunghwa Telecom Co Ltd, Telecommun Lab, Taipei, Taiwan
关键词
SSDLC; security testing tool; vulnerability analysis; integrated framework;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Hundreds of vulnerabilities and security defects are disclosed by hackers, developers, and users. The better way to improve software security is to enhance security process into SDLC processes. To keep software secure, security enhancement of the SDLC process involves lots of practices and activities to achieve goal of security. However, how to adopt these activities well to improve software security is an important problem. In this paper, we propose an integrated security testing framework for secure software development life cycle. In our proposed framework, we apply security activities and practices of SSDLC to generate security guidelines. Furthermore, we integrate security testing tools as a platform to provide testing service and converge testing results of tools to improve accurate of test. To evaluate our proposed framework, we construct the prototype system by referring phases of framework. Our system can integrate various security testing tools and support secure activities in each phase of SSDLC. We had applied our system to at least 50 software developing projects. The results indicate that our prototype system can provide quality and stable service.
引用
下载
收藏
页数:4
相关论文
共 50 条
  • [21] Current Taxonomy of Information Security Threats in Software Development Life Cycle
    Barabanov, Alexander V.
    Markov, Alexey S.
    Grishin, Maksim I.
    Tsirlov, Valentin L.
    2018 IEEE 12TH INTERNATIONAL CONFERENCE ON APPLICATION OF INFORMATION AND COMMUNICATION TECHNOLOGIES (AICT), 2018, : 196 - 201
  • [22] Using Special Use Cases for Security in the Software Development Life Cycle
    Tenday, Jean-Marie Kabasele
    INFORMATION SECURITY APPLICATIONS, 2011, 6513 : 122 - 134
  • [23] Security Considerations for the Development of Secure Software Systems
    Ruggieri, Maxwell
    Hsu, Tzu-Tang
    Ali, Md Liakat
    2019 IEEE 10TH ANNUAL UBIQUITOUS COMPUTING, ELECTRONICS & MOBILE COMMUNICATION CONFERENCE (UEMCON), 2019, : 1187 - 1193
  • [24] Adopting security practices in software development process: Security testing framework for sustainable smart cities
    Mothanna, Yusuf
    Elmedany, Wael
    Hammad, Mustafa
    Ksantini, Riadh
    Sharif, Mhd Saeed
    COMPUTERS & SECURITY, 2024, 144
  • [25] An Integrated Model for Software Security Testing Requirements
    Hui, Zhanwei
    Huang, Song
    Liu, Xiaoming
    Rao, Liping
    FRONTIERS OF MANUFACTURING AND DESIGN SCIENCE II, PTS 1-6, 2012, 121-126 : 1891 - 1895
  • [26] Research on the Framework of the Software Development Security Testing System Based on the Attack Mode
    Ma, Ning
    BASIC & CLINICAL PHARMACOLOGY & TOXICOLOGY, 2020, 126 : 291 - 291
  • [27] Adaption of Integrated Secure Guide for Secure Software Development Lifecycle
    Lee, Ki-Hyun
    Park, Young B.
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2016, 10 (06): : 145 - 154
  • [28] Assuring Software Security Against Buffer Overflow Attacks in Embedded Software Development Life Cycle
    Park, Chul Su
    Lee, Jae Hee
    Seo, Seong Chae
    Kim, Byung Ki
    12TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY: ICT FOR GREEN GROWTH AND SUSTAINABLE DEVELOPMENT, VOLS 1 AND 2, 2010, : 787 - 790
  • [29] The ISDF Framework: Towards Secure Software Development
    Alkussayer, Abdulaziz
    Allen, William H.
    JOURNAL OF INFORMATION PROCESSING SYSTEMS, 2010, 6 (01): : 91 - 106
  • [30] An automation framework design for secure software development
    Mythily, M.
    Valarmathi, M. L.
    Durai, C. Anand Deva
    Rexie, J. A. M.
    JOURNAL OF SOFTWARE-EVOLUTION AND PROCESS, 2019, 31 (10)