An integrated security testing framework for Secure Software Development Life Cycle

被引:0
|
作者
Tung, Yuan-Hsin [1 ]
Lo, Sheng-Chen [1 ]
Shih, Jen-Feng [1 ]
Lin, Hung-Fu [1 ]
机构
[1] Chunghwa Telecom Co Ltd, Telecommun Lab, Taipei, Taiwan
关键词
SSDLC; security testing tool; vulnerability analysis; integrated framework;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Hundreds of vulnerabilities and security defects are disclosed by hackers, developers, and users. The better way to improve software security is to enhance security process into SDLC processes. To keep software secure, security enhancement of the SDLC process involves lots of practices and activities to achieve goal of security. However, how to adopt these activities well to improve software security is an important problem. In this paper, we propose an integrated security testing framework for secure software development life cycle. In our proposed framework, we apply security activities and practices of SSDLC to generate security guidelines. Furthermore, we integrate security testing tools as a platform to provide testing service and converge testing results of tools to improve accurate of test. To evaluate our proposed framework, we construct the prototype system by referring phases of framework. Our system can integrate various security testing tools and support secure activities in each phase of SSDLC. We had applied our system to at least 50 software developing projects. The results indicate that our prototype system can provide quality and stable service.
引用
下载
收藏
页数:4
相关论文
共 50 条
  • [41] A Framework for Testing Hardware-Software Security Architectures
    Dwoskin, Jeffrey S.
    Gomathisankaran, Mahadevan
    Chen, Yu-Yuan
    Lee, Ruby B.
    26TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE (ACSAC 2010), 2010, : 387 - 397
  • [42] SOFTWARE TESTING IN A SYSTEM-DEVELOPMENT PROCESS - A LIFE-CYCLE PERSPECTIVE
    LI, EY
    JOURNAL OF SYSTEMS MANAGEMENT, 1990, 41 (08): : 23 - 31
  • [43] An integrated approach to security in software development methodologies
    Raman, Abhay
    Muegge, Steven
    2008 CANADIAN CONFERENCE ON ELECTRICAL AND COMPUTER ENGINEERING, VOLS 1-4, 2008, : 1921 - 1924
  • [44] Security risks of global software development life cycle: Industry practitioner's perspective
    Khan, Rafiq Ahmad
    Khan, Siffat Ullah
    Akbar, Muhammad Azeem
    Alzahrani, Musaad
    JOURNAL OF SOFTWARE-EVOLUTION AND PROCESS, 2024, 36 (03)
  • [45] A neuro-fuzzy security risk assessment system for software development life cycle
    Olusanya, Olayinka Olufunmilayo
    Jimoh, Rasheed Gbenga
    Misra, Sanjay
    Awotunde, Joseph Bamidele
    HELIYON, 2024, 10 (13)
  • [46] The Application of a New Secure Software Development Life Cycle (S-SDLC) with Agile Methodologies
    de Vicente Mohino, Juan
    Bermejo Higuera, Javier
    Bermejo Higuera, Juan Ramon
    Sicilia Montalvo, Juan Antonio
    ELECTRONICS, 2019, 8 (11)
  • [47] Mapping the field of software life cycle security metrics
    Morrison, Patrick
    Moye, David
    Pandita, Rahul
    Williams, Laurie
    INFORMATION AND SOFTWARE TECHNOLOGY, 2018, 102 : 146 - 159
  • [48] Security risks: Management and mitigation in the software life cycle
    Gilliam, DP
    THIRTEENTH IEEE INTERNATIONAL WORKSHOPS ON ENABLING TECHNOLOGIES: INFRASTRUCTURE FOR COLLABORATIVE ENTERPRISES, PROCEEDINGS, 2004, : 211 - 216
  • [49] Integrated framework for incorporating sustainability design in software engineering life-cycle: An empirical study
    Saputri, Theresia Ratih Dewi
    Lee, Seok-Won
    Information and Software Technology, 2021, 129
  • [50] Integrated framework for incorporating sustainability design in software engineering life-cycle: An empirical study
    Saputri, Theresia Ratih Dewi
    Lee, Seok-Won
    INFORMATION AND SOFTWARE TECHNOLOGY, 2021, 129