Systematic Mapping of the Literature on Secure Software Development

被引:13
|
作者
Nina, Hernan [1 ,2 ]
Pow-Sang, Jose Antonio [1 ]
Villavicencio, Monica [3 ]
机构
[1] Pontificia Univ Catolica Peru, Maestria Informat, Lima 15088, Peru
[2] Univ Lima, Carrera Profes Ingn Sistemas, Lima 15023, Peru
[3] Escuela Super Politecn Litoral, Fac Ingn Elect & Computac, Guayaquil 090902, Ecuador
来源
IEEE ACCESS | 2021年 / 9卷
关键词
Software; Security; Systematics; Market research; Software engineering; Databases; Licenses; Software development; security; requirements; design; construction; testing; vulnerability; systematic mapping review;
D O I
10.1109/ACCESS.2021.3062388
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The accelerated growth in exploiting vulnerabilities due to errors or failures in the software development process is a latent concern in the Software Industry. In this sense, this study aims to provide an overview of the Secure Software Development trends to help identify topics that have been extensively studied and those that still need to be. Therefore, in this paper, a systematic mapping review with PICo search strategies was conducted. A total of 867 papers were identified, of which only 528 papers were selected for this review. The main findings correspond to the Software Requirements Security, where the Elicitation and Misuse Cases reported more frequently. In Software Design Security, recurring themes are security in component-based software development, threat model, and security patterns. In the Software Construction Security, the most frequent topics are static code analysis and vulnerability detection. Finally, in Software Testing Security, the most frequent topics are vulnerability scanning and penetration testing. In conclusion, there is a diversity of methodologies, models, and tools with specific objectives in each secure software development stage.
引用
收藏
页码:36852 / 36867
页数:16
相关论文
共 50 条
  • [1] Systematic Mapping of the Literature on Secure Software Development
    Nina, Hernan
    Pow-Sang, Jose Antonio
    Villavicencio, Monica
    [J]. IEEE Access, 2021, 9 : 36852 - 36867
  • [2] Costing Secure Software Development - A Systematic Mapping Study
    Venson, Elaine
    Guo, Xiaomeng
    Yan, Zidi
    Boehm, Barry
    [J]. 14TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES 2019), 2019,
  • [3] Systematic Mapping of the Literature on Smells in Software Development Requirements
    Castillo-Motta, Mayra-Alejandra
    Dorado-Cordoba, Ruben-Dario
    Pardo-Calvache, Cesar-Jesus
    Orozco-Garces, Carlos-Eduardo
    [J]. REVISTA FACULTAD DE INGENIERIA, UNIVERSIDAD PEDAGOGICA Y TECNOLOGICA DE COLOMBIA, 2023, 32 (63):
  • [4] Systematic Literature Review on Security Risks and its Practices in Secure Software Development
    Khan, Rafiq Ahmad
    Khan, Siffat Ullah
    Khan, Habib Ullah
    Ilyas, Muhammad
    [J]. IEEE ACCESS, 2022, 10 : 5456 - 5481
  • [5] Awareness Support in Distributed Software Development: A Systematic Review and Mapping of the Literature
    Steinmacher, Igor
    Chaves, Ana Paula
    Gerosa, Marco Aurelio
    [J]. COMPUTER SUPPORTED COOPERATIVE WORK-THE JOURNAL OF COLLABORATIVE COMPUTING AND WORK PRACTICES, 2013, 22 (2-3): : 113 - 158
  • [6] Awareness Support in Distributed Software Development: A Systematic Review and Mapping of the Literature
    Igor Steinmacher
    Ana Paula Chaves
    Marco Aurélio Gerosa
    [J]. Computer Supported Cooperative Work (CSCW), 2013, 22 : 113 - 158
  • [7] A Systematic Literature Mapping: risk-based testing in software development
    Bastidas, Maria, I
    Pardo, Cesar J.
    Ardila, Carlos A.
    [J]. INGENIERIA Y COMPETITIVIDAD, 2021, 23 (01):
  • [8] Design notations for secure software: a systematic literature review
    van den Berghe, Alexander
    Scandariato, Riccardo
    Yskout, Koen
    Joosen, Wouter
    [J]. SOFTWARE AND SYSTEMS MODELING, 2017, 16 (03): : 809 - 831
  • [9] Design notations for secure software: a systematic literature review
    Alexander van den Berghe
    Riccardo Scandariato
    Koen Yskout
    Wouter Joosen
    [J]. Software & Systems Modeling, 2017, 16 : 809 - 831
  • [10] A Systematic Mapping of Literature on Software Refactoring Tools
    Tavares, Cleiton Silva
    Ferreira, Fischer
    Figueiredo, Eduardo
    [J]. PROCEEDINGS OF THE 14TH BRAZILIAN SYMPOSIUM ON INFORMATION SYSTEMS (SBSI2018), 2018, : 81 - 88