Title
Security Requirement Representation Method For Confidence Of Systems And Networks
Abstract
Software vulnerability is a key determiner of confidence in computer systems and networks. Usually, software requirements are listed at the beginning of software design, whereas vulnerabilities appear only after development is complete and sometimes only after the system is operational. Therefore, the security requirements during the design stage should address software vulnerabilities. This paper presents a method of representing software vulnerabilities as atomic vulnerabilities (AVs): an AV is an undividable cause-unit of vulnerability, and a set of AVs and the relationships among them represent software vulnerabilities. The AV concept originates from system theory and modeling methodology. AVs and the relationships among them can be used to construct a behavioral model of systems and networks with a focus on vulnerability. The logical relationships among AVs are named vulnerability expressions (VXs). With all the accumulated VXs of the systems and networks, we can set security requirements that resolve or circumvent vulnerabilities effectively and reinforce confidence in system and network robustness. The contribution of this paper is to use the concepts of AV and VX to derive the security requirements considering software vulnerabilities for secure systems and networks. The requirement derived can be used to complement the vulnerable situation caused by software that is developed without cognizance of security consideration.
Year
DOI
Venue
2010
10.1142/S021819401000461X
INTERNATIONAL JOURNAL OF SOFTWARE ENGINEERING AND KNOWLEDGE ENGINEERING
Keywords
Field
DocType
Software vulnerability, security requirement, system theory, DEVS formalism, confidence of system, network
Data mining,Security through obscurity,Vulnerability (computing),Software design,Computer science,Software security assurance,Computer security,Vulnerability management,Software requirements specification,Secure coding,Software requirements
Journal
Volume
Issue
ISSN
20
1
0218-1940
Citations 
PageRank 
References 
0
0.34
8
Authors
3
Name
Order
Citations
PageRank
Hyung-Jong Kim127827.13
Huy Kang Kim232940.32
Hae Young Lee38614.93