Security Requirement Modeling Support System using Software Security Knowledge Base

被引:3
|
作者
Hazeyama, Atsuo [1 ]
Tanaka, Shun'chi [2 ]
Tanaka, Takafumi [3 ]
Hashiura, Hiroaki [4 ]
Munetoh, Seiji [5 ]
Okubo, Takao [6 ]
Kaiya, Haruhiko [7 ]
Washizaki, Hironori [8 ]
Yoshioka, Nobukazu [9 ]
机构
[1] Tokyo Gakugei Univ, Dept Informat Sci, Tokyo, Japan
[2] Tokyo Gakugei Univ, Dept Informat Educ, Tokyo, Japan
[3] Tokyo Univ Agr & Technol, Grad Sch Engn, Tokyo, Japan
[4] Nippon Inst Technol, Fac Engn, Saitama, Japan
[5] IBM Japan Ltd, Fujisawa, Kanagawa, Japan
[6] Inst Informat Secur, Grad Sch Informat Secur, Yokohama, Kanagawa, Japan
[7] Kanagawa Univ, Dept Informat Sci, Yokohama, Kanagawa, Japan
[8] Waseda Univ, Dept Comp Sci & Engn, Tokyo, Japan
[9] Natl Inst Informat, Informat Syst Architecture Sci Res Div, Tokyo, Japan
关键词
Secure software development support; security requirements analysis; modeling support system; knowledge base for secure software development;
D O I
10.1109/COMPSAC.2018.10235
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
With the growing number of services on the Internet, the need for secure software development has increased. It is required for secure software development to consider security in the whole development life cycle. It is indispensable for secure software development to use various types of security knowledge. This study deals with security requirement analysis. Existing security requirements modeling systems do not provide a function to create an artifact while referring to security knowledge in an integrated manner. In this paper, the authors develop a modeling support system for a misuse case diagram that enables the association of knowledge with elements that constitute the diagram. The results of an experiment using the system show the system's usefulness in both the integration of the knowledge base with the artifact creation environment and the association of the knowledge with the elements of the diagram.
引用
收藏
页码:234 / 239
页数:6
相关论文
共 50 条
  • [1] A System for Seamless Support from Security Requirements Analysis to Security Design Using a Software Security Knowledge Base
    Hazeyama, Atsuo
    Miyahara, Hikaru
    Tanaka, Takafumi
    Washizaki, Hironori
    Kaiya, Haruhiko
    Okubo, Takao
    Yoshioka, Nobukazu
    2019 IEEE 27TH INTERNATIONAL REQUIREMENTS ENGINEERING CONFERENCE WORKSHOPS (REW 2019), 2019, : 134 - 140
  • [2] Case Base for Secure Software Development Using Software Security Knowledge Base
    Hazeyama, Atsuo
    Saito, Masahito
    Yoshioka, Nobukazu
    Kumagai, Azusa
    Kobashi, Takanori
    Washizaki, Hironori
    Kaiya, Haruhiko
    Okubo, Takao
    IEEE 39TH ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE WORKSHOPS (COMPSAC 2015), VOL 3, 2015, : 97 - 103
  • [3] Security in Software Engineering Requirement
    Al-Shorafat, Wafa Slaibi
    2013 8TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2013, : 666 - 673
  • [4] Knowledge for software security
    Barnum, S
    McGraw, G
    IEEE SECURITY & PRIVACY, 2005, 3 (02) : 74 - 78
  • [5] Knowledge Base for an Intelligent System in order to Identify Security Requirements for Government Agencies Software Projects
    Adan, Beltran G.
    Cristhian, Lombana C.
    Mario, Calvo L.
    Sonia, Ordonez S.
    Yaneth, Caviativa C.
    Jairo, Garces
    20TH INTERNATIONAL CONFERENCE ON CIRCUITS, SYSTEMS, COMMUNICATIONS AND COMPUTERS (CSCC 2016), 2016, 76
  • [6] OPERATING SYSTEM STRUCTURES TO SUPPORT SECURITY AND RELIABLE SOFTWARE
    LINDEN, TA
    COMPUTING SURVEYS, 1976, 8 (04) : 409 - 445
  • [7] A Case-based Management System for Secure Software Development Using Software Security Knowledge
    Saito, Masahito
    Hazeyama, Atsuo
    Yoshioka, Nobukazu
    Kobashi, Takanori
    Washizaki, Hironori
    Kaiya, Haruhiko
    Ohkubo, Takao
    KNOWLEDGE-BASED AND INTELLIGENT INFORMATION & ENGINEERING SYSTEMS 19TH ANNUAL CONFERENCE, KES-2015, 2015, 60 : 1092 - 1100
  • [8] Software Security and Systematizing Knowledge
    van Oorschot, Paul C.
    IEEE SECURITY & PRIVACY, 2019, 17 (03) : 4 - 6
  • [9] A Community Knowledge Base for IT Security
    Fenz, Stefan
    Parkin, Simon
    van Moorsel, Aad
    IT PROFESSIONAL, 2011, 13 (03) : 24 - 30
  • [10] A framework for security modeling using knowledge engineering
    Santana Torrellas, Gustavo A.
    WSEAS Transactions on Systems, 2006, 5 (04): : 760 - 765