Threat analysis in the software development lifecycle

被引:5
|
作者
Whitmore, J. [1 ]
Tuerpe, S. [2 ]
Triller, S. [2 ]
Poller, A. [2 ]
Carlson, C. [3 ]
机构
[1] IBM Software Grp, Mechanicsburg, PA 17011 USA
[2] Fraunhofer Inst Secure Informat Technol, Secur Test Lab, D-64295 Darmstadt, Germany
[3] IBM Software Grp, Minneapolis, MN 55402 USA
关键词
Assurance requirements - Current limitation - Development practices - Practical method - Security experts - Small community - Software assets - Software development life cycle;
D O I
10.1147/JRD.2013.2288060
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Businesses and governments that deploy and operate IT (information technology) systems continue to seek assurance that software they procure has the security characteristics they expect. The criteria used to evaluate the security of software are expanding from static sets of functional and assurance requirements to complex sets of evidence related to development practices for design, coding, testing, and support, plus consideration of security in the supply chain. To meet these evolving expectations, creators of software are faced with the challenge of consistently and continuously applying the most current knowledge about risks, threats, and weaknesses to their existing and new software assets. Yet the practice of threat analysis remains an art form that is highly subjective and reserved for a small community of security experts. This paper reviews the findings of an IBM-sponsored project with the Fraunhofer Institute for Secure Information Technology (SIT) and the Technische Universitat Darmstadt. This project investigated aspects of security in software development, including practical methods for threat analysis. The project also examined existing methods and tools, assessing their efficacy for software development within an open-source software supply chain. These efforts yielded valuable insights plus an automated tool and knowledge base that has the potential for overcoming some of the current limitations of secure development on a large scale.
引用
收藏
页数:13
相关论文
共 50 条
  • [1] Security in the Software Development Lifecycle
    Assal, Hala
    Chiasson, Sonia
    [J]. PROCEEDINGS OF THE FOURTEENTH SYMPOSIUM ON USABLE PRIVACY AND SECURITY, 2018, : 281 - 296
  • [2] A progressive software development lifecycle
    Turpin, R
    [J]. SECOND IEEE INTERNATIONAL CONFERENCE ON ENGINEERING OF COMPLEX COMPUTER SYSTEMS: HELD JOINTLY WITH 6TH CSESAW, 4TH IEEE RTAW, AND SES'96, 1996, : 208 - 211
  • [3] A Threat Intelligence Tool for the Security Development Lifecycle
    Kannavara, Raghudeep
    Vangore, Jacob
    Roberts, William
    Lindholm, Marcus
    Shrivastav, Priti
    [J]. PROCEEDINGS OF THE 12TH INNOVATIONS ON SOFTWARE ENGINEERING CONFERENCE (ISEC), 2019,
  • [4] Adherence to Secure Software Development Lifecycle
    Omar, Alaa'
    Alsadeh, Ahmad
    Nawahdah, Mamoun
    [J]. PROCEEDINGS OF THE 17TH INTERNATIONAL CONFERENCE ON SOFTWARE TECHNOLOGIES (ICSOFT), 2022, : 410 - 417
  • [5] Quantum software engineering and quantum software development lifecycle: a survey
    Dwivedi, Kanishk
    Haghparast, Majid
    Mikkonen, Tommi
    [J]. CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2024, 27 (06): : 7127 - 7145
  • [6] Simulating the Software Development Lifecycle: The Waterfall Model
    Saravanos, Antonios
    Curinga, Matthew X.
    [J]. APPLIED SYSTEM INNOVATION, 2023, 6 (06)
  • [7] Usability throughout the entire software development lifecycle
    Gulliksen, J
    Boivie, I
    [J]. HUMAN-COMPUTER INTERACTION - INTERACT'01, 2001, : 841 - 841
  • [8] Aspects of improvement of software development lifecycle management
    Klespitz, Jozsef
    Biro, Miklos
    Kovacs, Levente
    [J]. 2015 16TH IEEE INTERNATIONAL SYMPOSIUM ON COMPUTATIONAL INTELLIGENCE AND INFORMATICS (CINTI), 2015, : 323 - 327
  • [9] Automating Vulnerability Management in the Software Development Lifecycle
    Franca, Horacio L.
    Teixeira, Cesar
    laranjeiro, Nuno
    [J]. 2023 53RD ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS - SUPPLEMENTAL VOLUME, DSN-S, 2023, : 188 - 190
  • [10] Software Development Lifecycle for Energy Efficiency: Techniques and Tools
    Georgiou, Stefanos
    Rizou, Stamatia
    Spinellis, Diomidis
    [J]. ACM COMPUTING SURVEYS, 2019, 52 (04)