Mapping the field of software life cycle security metrics

被引:26
|
作者
Morrison, Patrick [1 ]
Moye, David [1 ]
Pandita, Rahul [1 ,2 ]
Williams, Laurie [1 ]
机构
[1] North Carolina State Univ, Raleigh, NC 27695 USA
[2] Phase Change Software LLC, Golden, CO USA
关键词
Metrics; Measurement; Security;
D O I
10.1016/j.infsof.2018.05.011
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Context: Practitioners establish a piece of software's security objectives during the software development process. To support control and assessment, practitioners and researchers seek to measure security risks and mitigations during software development projects. Metrics provide one means for assessing whether software security objectives have been achieved. A catalog of security metrics for the software development life cycle could assist practitioners in choosing appropriate metrics, and researchers in identifying opportunities for refinement of security measurement. Objective: The goal of this research is to support practitioner and researcher use of security measurement in the software life cycle by cataloging security metrics presented in the literature, their validation, and the subjects they measure. Method: We conducted a systematic mapping study, beginning with 4818 papers and narrowing down to 71 papers reporting on 324 unique security metrics. For each metric, we identified the subject being measured, how the metric has been validated, and how the metric is used. We categorized the metrics, and give examples of metrics for each category. Results: In our data, 85% of security metrics have been proposed and evaluated solely by their authors, leaving room for replication and confirmation through field studies. Approximately 60% of the metrics have been empirically evaluated, by their authors or by others. The available metrics are weighted heavily toward the implementation and operations phases, with relatively few metrics for requirements, design, and testing phases of software development. Some artifacts and processes remain unmeasured. Measured by phase, Testing received the least attention, with 1.5% of the metrics. Conclusions: At present, the primary application of security metrics to the software development life cycle in the literature is to study the relationship between properties of source code and reported vulnerabilities. The most-cited and most used metric, vulnerability count, has multiple definitions and operationalizations. We suggest that researchers must check vulnerability count definitions when making comparisons between papers. In addition to refining vulnerability measurement, we see research opportunities for greater attention to metrics for the requirement, design, and testing phases of development. We conjecture from our data that the field of software life cycle security metrics has yet to converge on an accepted set of metrics.
引用
收藏
页码:146 / 159
页数:14
相关论文
共 50 条
  • [41] A stake holder based model for software security metrics
    Sree Ram Kumar, T.
    Alagarsamy, K.
    International Journal of Computer Science Issues, 2011, 8 (02): : 444 - 448
  • [42] Using Security Metrics in Software Quality Assurance Process
    Abdi, Athena
    Souzani, Afshin
    Amirfakhri, Maliheh
    Moghadam, Azadeh Bamdad
    2012 SIXTH INTERNATIONAL SYMPOSIUM ON TELECOMMUNICATIONS (IST), 2012, : 1099 - 1102
  • [43] Security risks of global software development life cycle: Industry practitioner's perspective
    Khan, Rafiq Ahmad
    Khan, Siffat Ullah
    Akbar, Muhammad Azeem
    Alzahrani, Musaad
    JOURNAL OF SOFTWARE-EVOLUTION AND PROCESS, 2024, 36 (03)
  • [44] A neuro-fuzzy security risk assessment system for software development life cycle
    Olusanya, Olayinka Olufunmilayo
    Jimoh, Rasheed Gbenga
    Misra, Sanjay
    Awotunde, Joseph Bamidele
    HELIYON, 2024, 10 (13)
  • [45] A Systematic Mapping Study on Dynamic Metrics and Software Quality
    Tahir, Amjed
    MacDonell, Stephen G.
    2012 28TH IEEE INTERNATIONAL CONFERENCE ON SOFTWARE MAINTENANCE (ICSM), 2012, : 326 - 335
  • [46] Software Product Quality Metrics: A Systematic Mapping Study
    Colakoglu, Fatima Nur
    Yazici, Ali
    Mishra, Alok
    IEEE ACCESS, 2021, 9 (09): : 44647 - 44670
  • [47] Green Metrics to Software Development Organizations: A Systematic Mapping
    Welter, Marcio
    Vavassori Benitti, Fabiane Barreto
    Thiry, Marcello
    PROCEEDINGS OF THE 2014 XL LATIN AMERICAN COMPUTING CONFERENCE (CLEI), 2014,
  • [48] Metrics to Quantify Software Developer Experience: a Systematic Mapping*
    Brasil-Silva, Renata
    Siqueira, Fabio Levy
    37TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, 2022, : 1562 - 1569
  • [49] Life-cycle software
    Hughes, D
    AVIATION WEEK & SPACE TECHNOLOGY, 2003, 159 (07): : 57 - 59
  • [50] Conceptualizing Software Life Cycle
    Al-Fedaghi, Sabah S.
    INFORMATION SYSTEMS: MODELING, DEVELOPMENT, AND INTEGRATION, 2009, 20 : 438 - 457