Security patterns: A systematic mapping study

被引:8
|
作者
Jafari, Abbas Javan [1 ]
Rasoolzadegan, Abbas [1 ]
机构
[1] Ferdowsi Univ Mashhad, Dept Comp Engn, Fac Engn, Mashhad, Razavi Khorasan, Iran
关键词
Security patterns; Systematic review; Mapping study; Secure software development; DESIGN PATTERNS; SOFTWARE; DRIVEN;
D O I
10.1016/j.cola.2019.100938
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Security patterns are a well-established means to encapsulate and communicate proven security solutions and introduce security into the development process. Our objective is to explore the research efforts on security patterns and discuss the current state of the art, which will serve as a guideline for interested researchers, practitioners, and teachers. We have conducted a systematic mapping study of relevant literature from 1997 until the end of 2017 and identified 403 relevant papers, 274 of which were selected for analysis based on quality criteria. This study derives a customized research strategy from established systematic approaches in the literature. The first 3 research questions address the demographics of security pattern research such as topic classification, trends, and distribution between academia and industry, along with prominent researchers and venues. The next 9 research questions focus on more in-depth analyses such as pattern presentation notations and classification criteria, pattern evaluation techniques, and pattern usage environments. We observe that security pattern research is an active and growing field and the patterns are increasingly being used to improve software development approaches. Pattern evaluation is currently the least explored topic by researchers and there is a lack of empirical studies in the field.
引用
收藏
页数:24
相关论文
共 50 条
  • [1] A Systematic Mapping of Patterns and Architectures for IoT Security
    Rajmohan, Tanusan
    Nguyen, Phu H.
    Ferry, Nicolas
    [J]. PROCEEDINGS OF THE 5TH INTERNATIONAL CONFERENCE ON INTERNET OF THINGS, BIG DATA AND SECURITY (IOTBDS), 2020, : 138 - 149
  • [2] A systematic mapping study on security for systems of systems
    Olivero, Miguel Angel
    Bertolino, Antonia
    Dominguez-Mayo, Francisco Jose
    Escalona, Maria Jose
    Matteucci, Ilaria
    [J]. INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2024, 23 (02) : 787 - 817
  • [3] Security and Privacy for Blockchain: A Systematic Mapping Study
    Yang, Jinmei
    Bi, Huang
    Dai, Fei
    Liang, Zhihong
    Qiang, Zhenping
    [J]. 2021 IEEE INTL CONF ON DEPENDABLE, AUTONOMIC AND SECURE COMPUTING, INTL CONF ON PERVASIVE INTELLIGENCE AND COMPUTING, INTL CONF ON CLOUD AND BIG DATA COMPUTING, INTL CONF ON CYBER SCIENCE AND TECHNOLOGY CONGRESS DASC/PICOM/CBDCOM/CYBERSCITECH 2021, 2021, : 446 - 453
  • [4] Security In The Internet Of Things - A Systematic Mapping Study
    Porras, Jari
    Pankalainen, Jouni
    Knutas, Antti
    Khakurel, Jayden
    [J]. PROCEEDINGS OF THE 51ST ANNUAL HAWAII INTERNATIONAL CONFERENCE ON SYSTEM SCIENCES (HICSS), 2018, : 3750 - 3759
  • [5] A systematic mapping study of usability vs security
    Merdanoglu, Nur
    Onay Durdu, Pinar
    [J]. 2018 6TH INTERNATIONAL CONFERENCE ON CONTROL ENGINEERING & INFORMATION TECHNOLOGY (CEIT), 2018,
  • [6] A systematic mapping study on security for systems of systems
    Miguel Angel Olivero
    Antonia Bertolino
    Francisco José Dominguez-Mayo
    María José Escalona
    Ilaria Matteucci
    [J]. International Journal of Information Security, 2024, 23 : 787 - 817
  • [7] Architectural Patterns for Microservices: A Systematic Mapping Study
    Taibi, Davide
    Lenarduzzi, Valentina
    Pahl, Claus
    [J]. CLOSER: PROCEEDINGS OF THE 8TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING AND SERVICES SCIENCE, 2018, : 221 - 232
  • [8] Modelling Security Aspects with ArchiMate: A Systematic Mapping Study
    Ellerm, Augustus
    Morales-Trujillo, Miguel Ehecatl
    [J]. 2020 46TH EUROMICRO CONFERENCE ON SOFTWARE ENGINEERING AND ADVANCED APPLICATIONS (SEAA 2020), 2020, : 577 - 584
  • [9] A Systematic Mapping Study on Security in Agile Requirements Engineering
    Villamizar, Hugo
    Kalinowski, Marcos
    Viana, Marx
    Fernandez, Daniel Mendez
    [J]. 44TH EUROMICRO CONFERENCE ON SOFTWARE ENGINEERING AND ADVANCED APPLICATIONS (SEAA 2018), 2018, : 454 - 461
  • [10] Cyber Security Threats and Vulnerabilities: A Systematic Mapping Study
    Humayun, Mamoona
    Niazi, Mahmood
    Jhanjhi, N. Z.
    Alshayeb, Mohammad
    Mahmood, Sajjad
    [J]. ARABIAN JOURNAL FOR SCIENCE AND ENGINEERING, 2020, 45 (04) : 3171 - 3189