A new, evidence-based, theory for knowledge reuse in security risk analysis

被引:1
|
作者
Labunets, Katsiaryna [1 ]
Massacci, Fabio [2 ,3 ]
Paci, Federica [4 ]
Tuma, Katja [2 ]
机构
[1] Univ Utrecht, Utrecht, Netherlands
[2] Vrije Univ Amsterdam, Amsterdam, Netherlands
[3] Univ Trento, Trento, Italy
[4] Univ Verona, Verona, Italy
关键词
Information security; Risk assessment; Empirical study; Knowledge reuse; THREAT ANALYSIS; ATTACK TREES; MANAGEMENT; COMMUNITIES; DISCOURSES; SYSTEMS; IF;
D O I
10.1007/s10664-023-10321-y
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Security risk analysis (SRA) is a key activity in software engineering but requires heavy manual effort. Community knowledge in the form of security patterns or security catalogs can be used to support the identification of threats and security controls. However, no evidence-based theory exists about the effectiveness of security catalogs when used for security risk analysis. We adopt a grounded theory approach to propose a conceptual, revised and refined theory of SRA knowledge reuse. The theory refinement is backed by evidence gathered from conducting interviews with experts (20) and controlled experiments with both experts (15) and novice analysts (18). We conclude the paper by providing insights into the use of catalogs and managerial implications.
引用
收藏
页数:33
相关论文
共 50 条
  • [21] Evaluation and reliability analysis of network security risk factors based on D-S evidence theory
    Yu, Jingjie
    Hu, Min
    Wang, Peng
    JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2018, 34 (02) : 861 - 869
  • [22] Evidence-based framework for a theory of inheritance
    1600, Morgan Kaufmann Publ Inc, San Mateo, CA, USA (02):
  • [23] Where is the theory in evidence-based practice?
    Schmelzer, Marilee
    GASTROENTEROLOGY NURSING, 2007, 30 (06) : 446 - 448
  • [24] Evidence-Based Practice and Nursing Theory
    Karnick, Paula M.
    NURSING SCIENCE QUARTERLY, 2016, 29 (04) : 283 - 284
  • [25] Theory guided evidence-based practice
    Pittman, Joyce
    Uphold, Brenda
    Atwell, Nancy
    JOURNAL OF WOUND OSTOMY AND CONTINENCE NURSING, 2007, 34 (03) : S55 - S55
  • [26] Evidence-based framework for a theory of inheritance
    1600, Morgan Kaufmann Publ Inc, San Mateo, CA, USA (02):
  • [27] Evidence-based medicine or just a theory?
    Kol, Shahar
    Lightman, Avraham
    Itskovitz-Eldor, Joseph
    FERTILITY AND STERILITY, 2009, 92 (01) : E9 - E9
  • [28] Evidence-Based Analysis of Cyber Attacks to Security Monitored Distributed Energy Resources
    Cerotti, Davide
    Codetta-Raiteri, Daniele
    Dondossola, Giovanna
    Egidi, Lavinia
    Franceschinis, Giuliana
    Portinale, Luigi
    Terruggia, Roberta
    APPLIED SCIENCES-BASEL, 2020, 10 (14):
  • [29] Risk Analysis of Information System Security Based on the Evidence Distance
    LingHu, Jinhua
    Pan, Ping
    Du, Yaoyao
    PROCEEDINGS OF THE 11TH INTERNATIONAL CONFERENCE ON MODELLING, IDENTIFICATION AND CONTROL (ICMIC2019), 2020, 582 : 347 - 358
  • [30] New: Working Group publishes evidence-based Knowledge Catalog on the Topic of Sorrow
    Mueller, Heidi
    Kiepke-Ziemes, Susanne
    Kersting, Eva
    Muench, Urs
    ZEITSCHRIFT FUR PALLIATIVMEDIZIN, 2021, 22 (06): : 292 - 293