Title
Developing Abuse Cases Based on Threat Modeling and Attack Patterns.
Abstract
Developing abuse cases help software engineers to think from the perspective of attackers, and therefore allow them to decide and document how the software should react to illegitimate use. This paper describes a method for developing abuse cases based on threat modeling and attack patterns. First potential threats are analyzed by following Microsoftu0027s threat modeling process. Based on the identified threats, initial abuse cases are generated. Attack pattern library is searched and attack patterns relevant to the abuse cases are retrieved. The information retrieved from the attack patterns are used to extend the initial abuse cases and suggest mitigation method. Such a method has the potential to assist software engineers without high expertise in computer security to develop meaningful and useful abuse cases, and therefore reduce the security vulnerabilities in the software systems they develop.
Year
Venue
Field
2015
JSW
Internet privacy,Attack patterns,Threat model,Computer science,Computer security,Software system,Software,Vulnerability
DocType
Volume
Issue
Journal
10
4
Citations 
PageRank 
References 
3
0.47
4
Authors
4
Name
Order
Citations
PageRank
Xiaohong Yuan116926.72
Emmanuel Borkor Nuakoh260.98
Imano Williams342.84
Huiming Yu46514.25