Reducing software security risk through an integrated approach

被引:1
|
作者
Gilliam, DP [1 ]
Powell, JD [1 ]
Kelly, JC [1 ]
Bishop, M [1 ]
机构
[1] CALTECH, Jet Prop Lab, Pasadena, CA 91125 USA
关键词
security toolset; vulnerability matrix; property-based testing; model checking; security; verification;
D O I
10.1109/SEW.2001.992653
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
This paper presents joint work by the California Institute of Technology's Jet Propulsion Laboratory and the University of California at Davis (UC Davis) sponsored by the National Aeronautics and Space Administration Goddard Independent Verification and Validation Facility to develop a security assessment instrument for the software development and maintenance life Cycle. Vulnerabilities in operating systems and software applications render an otherwise secure environment insecure. Any operating system or application added to a secure environment that has exploitable security vulnerabilities affects the security of the whole environment. An otherwise secure system can be compromised easily if the system or application software on it, or on a linked system, has vulnerabilities. Therefore, it is critical that software on networked computer systems be free from security vulnerabilities. Security, vulnerabilities in software arise from a number of development factors; but these vulnerabilities can generally be traced to poor software development practices, new modes of attacks, mis-configurations, and unsecured links between systems. A Software security assessment instrument can aid in providing a greater level of assurance that software is not exposed to vulnerabilities as a result of defective software requirements, designs, code or exposures due to code complexity, and integration with other applications that are network aware. This paper presents research on the generation of a software security assessment instrument to aid developers in assessing and assuring the security of software in the development and maintenance lifecycles. The research presented here is available at: http://security.jpl.nasa.gov/rssr.
引用
收藏
页码:36 / 42
页数:7
相关论文
共 50 条
  • [1] Reducing software security risk through an integrated approach
    Gilliam, DP
    Kelly, JC
    Bishop, M
    IEEE 9TH INTERNATIONAL WORKSHOPS ON ENABLING TECHNOLOGIES: INFRASTRUCTURE FOR COLLABORATIVE ENTERPRISES, PROCEEDINGS, 2000, : 141 - 146
  • [2] Improving software security through an integrated approach
    Gan, Zaobin
    Wei, Dengwei
    Varadharajan, Vijay
    SECRYPT 2006: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, 2006, : 437 - +
  • [3] An integrated approach to security in software development methodologies
    Raman, Abhay
    Muegge, Steven
    2008 CANADIAN CONFERENCE ON ELECTRICAL AND COMPUTER ENGINEERING, VOLS 1-4, 2008, : 1921 - 1924
  • [4] Managing Software Security Risks through an Integrated Computational
    Alharbi, Abdullah
    Alosaimi, Wael
    Alyami, Hashem
    Nadeem, Mohd
    Faizan, Mohd
    Agrawal, Alka
    Kumar, Rajeev
    Khan, Raees Ahmad
    INTELLIGENT AUTOMATION AND SOFT COMPUTING, 2021, 28 (01): : 179 - 194
  • [5] Reducing adolescent risk: Towards an integrated approach
    Curtis, K
    HEALTH RISK & SOCIETY, 2005, 7 (04) : 414 - 415
  • [6] Reducing cost through an integrated approach to power and automation
    O'Brien, Larry
    HYDROCARBON PROCESSING, 2009, 88 (04): : 13 - 13
  • [7] PRISM: A Preventive and Risk-Reducing Integrated Security Management Model Using Security Label
    D. S. Kim
    Y. J. Jung
    T. M. Chung
    The Journal of Supercomputing, 2005, 33 : 103 - 121
  • [8] PRISM: A preventive and risk-reducing integrated security management model using security label
    D. S. Kim
    Y. J. Jung
    T. M. Chung
    The Journal of Supercomputing, 2005, 33 (1-2) : 103 - 121
  • [9] PRISM: A preventive and risk-reducing integrated security management model using security label
    Kim, DS
    Jung, YJ
    Chung, TM
    JOURNAL OF SUPERCOMPUTING, 2005, 33 (1-2): : 103 - 121
  • [10] Reducing Acquisition Risk through Integrated Systems of Systems Engineering
    Gross, Andrew
    Hobson, Brian
    Bouwens, Christina
    MODELING AND SIMULATION FOR DEFENSE SYSTEMS AND APPLICATIONS XI, 2016, 9848