Prioritizing Countermeasures through the Countermeasure Method for Software Security (CM-Sec)

被引:0
|
作者
Baca, Dejan [1 ]
Petersen, Kai [1 ]
机构
[1] Blekinge Inst Technol, SE-37225 Ronneby, Sweden
关键词
ATTACK TREES;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Software security is an important quality aspect of a software system. Therefore, it is important to integrate software security touch points throughout the development life-cycle. So far, the focus of touch points in the early phases has been on the identification of threats and attacks. In this paper we propose a novel method focusing on the end product by prioritizing countermeasures. The method provides an extension to attack trees and a process for identification and prioritization of countermeasures. The approach has been applied on an open-source application and showed that countermeasures could be identified. Furthermore, an analysis of the effectiveness and cost-efficiency of the countermeasures could be provided.
引用
收藏
页码:176 / 190
页数:15
相关论文
empty
未找到相关数据