An integrated security testing framework for Secure Software Development Life Cycle

被引:0
|
作者
Tung, Yuan-Hsin [1 ]
Lo, Sheng-Chen [1 ]
Shih, Jen-Feng [1 ]
Lin, Hung-Fu [1 ]
机构
[1] Chunghwa Telecom Co Ltd, Telecommun Lab, Taipei, Taiwan
关键词
SSDLC; security testing tool; vulnerability analysis; integrated framework;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Hundreds of vulnerabilities and security defects are disclosed by hackers, developers, and users. The better way to improve software security is to enhance security process into SDLC processes. To keep software secure, security enhancement of the SDLC process involves lots of practices and activities to achieve goal of security. However, how to adopt these activities well to improve software security is an important problem. In this paper, we propose an integrated security testing framework for secure software development life cycle. In our proposed framework, we apply security activities and practices of SSDLC to generate security guidelines. Furthermore, we integrate security testing tools as a platform to provide testing service and converge testing results of tools to improve accurate of test. To evaluate our proposed framework, we construct the prototype system by referring phases of framework. Our system can integrate various security testing tools and support secure activities in each phase of SSDLC. We had applied our system to at least 50 software developing projects. The results indicate that our prototype system can provide quality and stable service.
引用
收藏
页数:4
相关论文
共 50 条
  • [31] Addressing software security and mitigations in the life cycle
    Gilliam, D
    Powell, J
    Haugh, E
    Bishop, M
    28TH ANNUAL NASA GODDARD SOFTWARE ENGINEERING WORKSHOP, PROCEEDINGS, 2004, : 201 - 206
  • [32] PUF Based Secure Framework for Hardware and Software Security of Drones
    Pal, Vishal
    Acharya, B Srikrishna
    Shrivastav, Somesh
    Saha, Sourav
    Joglekar, Ashish
    Amrutur, Bharadwaj
    Proceedings of the 2020 Asian Hardware Oriented Security and Trust Symposium, AsianHOST 2020, 2020,
  • [33] A security pattern detection framework for building more secure software
    Alvi, Aleem Khalid
    Zulkernine, Mohammad
    JOURNAL OF SYSTEMS AND SOFTWARE, 2021, 171 (171)
  • [34] PUF Based Secure Framework for Hardware and Software Security of Drones
    Pal, Vishal
    Acharya, B. Srikrishna
    Shrivastav, Somesh
    Saha, Sourav
    Joglekar, Ashish
    Amrutur, Bharadwaj
    PROCEEDINGS OF THE 2020 ASIAN HARDWARE ORIENTED SECURITY AND TRUST SYMPOSIUM (ASIANHOST), 2020,
  • [35] Security-aware Software Development Life Cycle (SaSDLC) - Processes and Tools
    Talukder, Asoke K.
    Maurya, Vineet Kumar
    Babu, Santhosh G.
    Ebenezer, Jangam
    Sekhar, Muni, V
    Jevitha, K. P.
    Samanta, Saurabh
    Pais, Alwyn Roshan
    WOCN: 2009 IFIP INTERNATIONAL CONFERENCE ON WIRELESS AND OPTICAL COMMUNICATIONS NETWORKS, 2009, : 253 - 257
  • [36] Static Analysis for Web Service Security - Tools & Techniques for a Secure Development Life Cycle
    Masood, Adnan
    Java, Jim
    2015 IEEE INTERNATIONAL SYMPOSIUM ON TECHNOLOGIES FOR HOMELAND SECURITY (HST), 2015,
  • [37] The Study of the Effectiveness of the Secure Software Development Life-Cycle Models in IT Project Management
    Duclervil, Saniora R.
    Liou, Jing-Chiou
    16TH INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY-NEW GENERATIONS (ITNG 2019), 2019, 800 : 91 - 96
  • [38] An Integrated Framework for Life Cycle Engineering
    Hauschild, Michael Z.
    Herrmann, Christoph
    Kara, Sami
    24TH CIRP CONFERENCE ON LIFE CYCLE ENGINEERING, 2017, 61 : 2 - 9
  • [39] A Framework for the Development and Testing of Cryptographic Software
    Burnett, Andrew
    Dowling, Tom
    ADVANCES IN COMPUTER AND INFORMATIOM SCIENCES AND ENGINEERING, 2008, : 45 - 50
  • [40] IoT Security A Comprehensive Life Cycle Framework
    Bertino, Elisa
    2019 IEEE 5TH INTERNATIONAL CONFERENCE ON COLLABORATION AND INTERNET COMPUTING (CIC 2019), 2019, : 196 - 203