Quantitative Security Assurance Metrics - REST API Case Studies

被引:5
|
作者
Katt, Basel [1 ]
Prasher, Nishu [2 ]
机构
[1] Norwegian Univ Sci & Technol NTNU, Trondheim, Norway
[2] Stat Norway, Div Qual & Team Management, Oslo, Norway
关键词
Security metric; security assurance; security testing; REST API;
D O I
10.1145/3241403.3241464
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Security assurance is the confidence that a system meets its security requirements based on specific evidences that an assurance technique provide. The notion of measuring security is complex and tricky. Existing approaches either (1) consider one aspect of assurance, like security requirements fulfillment, or threat/vulnerability existence, or (2) do not consider the relevance of the different security requirements to the evaluated application context. Furthermore, they are mostly qualitative in nature and are heavily based on manual processing, which make them costly and time consuming. Therefore, they are not widely used and applied, especially by small and medium-sized enterprises (SME), which constitute the backbone of the Norwegian economy. In this paper, we propose a quantification method that aims at evaluating security assurance of systems by measuring (1) the level of confidence that the mechanisms fulfilling security requirements are present and (2) the vulnerabilities associated with possible security threats are absent. Additionally, an assurance evaluation process is proposed. Two case studies applying our method are presented. The case studies use our assurance method to evaluate the security level of two REST APIs developed by Statistics Norway, where one of the authors is employed. Analysis shows that the API with the most security mechanisms implemented got a slightly higher security assurance score. Security requirement relevance and vulnerability impact played a role in the overall scores.
引用
收藏
页数:7
相关论文
共 50 条
  • [1] Assurance cases for security: The metrics challenge
    Bloomfield, Robin
    Masera, Marcelo
    Miller, Ann
    Saydjari, O. Sami
    Weinstock, Charles B.
    [J]. 37TH ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS, PROCEEDINGS, 2007, : 807 - 808
  • [2] Towards Security Assurance Metrics for Service Systems Security
    Ouedraogo, Moussa
    [J]. EXPLORING SERVICES SCIENCE, 2012, 103 : 361 - 370
  • [3] Quantitative Security Assurance Case for In-vehicle Embedded Systems
    Zhou, Zhengshu
    Matsubara, Yutaka
    Takada, Hiroaki
    [J]. 2021 IEEE INTL CONF ON DEPENDABLE, AUTONOMIC AND SECURE COMPUTING, INTL CONF ON PERVASIVE INTELLIGENCE AND COMPUTING, INTL CONF ON CLOUD AND BIG DATA COMPUTING, INTL CONF ON CYBER SCIENCE AND TECHNOLOGY CONGRESS DASC/PICOM/CBDCOM/CYBERSCITECH 2021, 2021, : 43 - 50
  • [4] On the Security Expressiveness of REST-Based API Definition Languages
    Hoai Viet Nguyen
    Tolsdorf, Jan
    Lo Iacono, Luigi
    [J]. TRUST, PRIVACY AND SECURITY IN DIGITAL BUSINESS, TRUSTBUS 2017, 2017, 10442 : 215 - 231
  • [5] Taxonomy of quality metrics for assessing assurance of security correctness
    Moussa Ouedraogo
    Reijo M. Savola
    Haralambos Mouratidis
    David Preston
    Djamel Khadraoui
    Eric Dubois
    [J]. Software Quality Journal, 2013, 21 : 67 - 97
  • [6] Taxonomy of quality metrics for assessing assurance of security correctness
    Ouedraogo, Moussa
    Savola, Reijo M.
    Mouratidis, Haralambos
    Preston, David
    Khadraoui, Djamel
    Dubois, Eric
    [J]. SOFTWARE QUALITY JOURNAL, 2013, 21 (01) : 67 - 97
  • [7] Using Security Metrics in Software Quality Assurance Process
    Abdi, Athena
    Souzani, Afshin
    Amirfakhri, Maliheh
    Moghadam, Azadeh Bamdad
    [J]. 2012 SIXTH INTERNATIONAL SYMPOSIUM ON TELECOMMUNICATIONS (IST), 2012, : 1099 - 1102
  • [8] A quantitative framework for security assurance evaluation and selection of cloud services: a case study
    Ankur Shukla
    Basel Katt
    Muhammad Mudassar Yamin
    [J]. International Journal of Information Security, 2023, 22 : 1621 - 1650
  • [9] A quantitative framework for security assurance evaluation and selection of cloud services: a case study
    Shukla, Ankur
    Katt, Basel
    Yamin, Muhammad Mudassar
    [J]. INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2023, 22 (06) : 1621 - 1650
  • [10] ARIMA Supplemented Security Metrics for Quality Assurance and Situational Awareness
    Kohlrausch, Jan
    Brin, Eugene A.
    [J]. DIGITAL THREATS: RESEARCH AND PRACTICE, 2020, 1 (01):