A fuzzy framework for prioritization and partial selection of security requirements in software projects

被引:6
|
作者
Mougouei, Davoud [1 ]
Powers, David M. W. [2 ]
Mougouei, Elahe [3 ]
机构
[1] Monash Univ, Fac IT, Melbourne, Vic, Australia
[2] Flinders Univ S Australia, Coll Sci & Engn, Adelaide, SA, Australia
[3] Islamic Azad Univ, Fac Comp Engn, Esfahan, Iran
关键词
Security; Requirements; Partial Selection; Fuzzy; INFERENCE; MAMDANI; MODEL; SYSTEMS;
D O I
10.3233/JIFS-182907
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Resource limitations in software projects rarely allow for the security requirements to be fully realized. As such, Prioritization and Selection (PAS) techniques are used to find an optimal subset of the requirements. Consequently, some of the security requirements will be ignored. But ignoring security requirements may (a) leave some of the security threats unattended and (b) negatively impact the effectiveness of the selected requirements. To mitigate this, we have proposed a fuzzy framework, referred to as Prioritization And Partial Selection (PAPS), that reduces the number of ignored security requirements by allowing for partial satisfaction of those requirements. We achieve this by relaxing the satisfaction conditions of security requirements, when tolerated, based on their priorities specified by a fuzzy inference system. Taking into account the partiality of security in PAPS mitigates the adverse impact of ignoring security requirements and enhances the accuracy of prioritization and selection. Our proposed framework is scalable to a large number of requirements.
引用
收藏
页码:2671 / 2686
页数:16
相关论文
共 50 条
  • [1] Partial Selection of Software Requirements: A Fuzzy Method
    Davoud Mougouei
    Elahe Mougouei
    David M. W. Powers
    International Journal of Fuzzy Systems, 2021, 23 : 2067 - 2079
  • [2] Partial Selection of Software Requirements: A Fuzzy Method
    Mougouei, Davoud
    Mougouei, Elahe
    Powers, David M. W.
    INTERNATIONAL JOURNAL OF FUZZY SYSTEMS, 2021, 23 (07) : 2067 - 2079
  • [3] RePizer: a framework for prioritization of software requirements
    Khan, Saif Ur Rehman
    Lee, Sai Peck
    Dabbagh, Mohammad
    Tahir, Muhammad
    Khan, Muzafar
    Arif, Muhammad
    FRONTIERS OF INFORMATION TECHNOLOGY & ELECTRONIC ENGINEERING, 2016, 17 (08) : 750 - 765
  • [4] RePizer: a framework for prioritization of software requirements
    Saif Ur Rehman Khan
    Sai Peck Lee
    Mohammad Dabbagh
    Muhammad Tahir
    Muzafar Khan
    Muhammad Arif
    Frontiers of Information Technology & Electronic Engineering, 2016, 17 : 750 - 765
  • [5] A Framework for Prioritization and Selection of Strategic Projects
    Al-Sobai, Khalifa Mohammed
    Pokharel, Shaligram
    Abdella, Galal M.
    IEEE TRANSACTIONS ON ENGINEERING MANAGEMENT, 2024, 71 : 2310 - 2323
  • [6] Generating large dataset for software requirements prioritization and selection under fuzzy environment
    Nazim, Mohd.
    Arif, Mohd.
    Mohammad, Chaudhary Wali
    Sadiq, Mohd.
    JOURNAL OF INFORMATION & OPTIMIZATION SCIENCES, 2023, 44 (02): : 285 - 299
  • [7] A Partial Order Assimilation Approach for Software Requirements Prioritization
    Easmin, Rubaida
    Ul Gias, Alim
    Khaled, Shah Mostafa
    2014 INTERNATIONAL CONFERENCE ON INFORMATICS, ELECTRONICS & VISION (ICIEV), 2014,
  • [8] A framework for prioritization of quality requirements for inclusion in a software project
    Rahul Thakurta
    Software Quality Journal, 2013, 21 : 573 - 597
  • [10] Fuzzy Cloud Access Security Broker for Requirements Negotiation and Prioritization
    Ahmad, Shahnawaz
    Mehfuz, Shabana
    Beg, Javed
    2019 INTERNATIONAL CONFERENCE ON POWER ELECTRONICS, CONTROL AND AUTOMATION (ICPECA-2019), 2019, : 147 - 152