Reducing software security risk through an integrated approach

被引:1
|
作者
Gilliam, DP [1 ]
Powell, JD [1 ]
Kelly, JC [1 ]
Bishop, M [1 ]
机构
[1] CALTECH, Jet Prop Lab, Pasadena, CA 91125 USA
关键词
security toolset; vulnerability matrix; property-based testing; model checking; security; verification;
D O I
10.1109/SEW.2001.992653
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
This paper presents joint work by the California Institute of Technology's Jet Propulsion Laboratory and the University of California at Davis (UC Davis) sponsored by the National Aeronautics and Space Administration Goddard Independent Verification and Validation Facility to develop a security assessment instrument for the software development and maintenance life Cycle. Vulnerabilities in operating systems and software applications render an otherwise secure environment insecure. Any operating system or application added to a secure environment that has exploitable security vulnerabilities affects the security of the whole environment. An otherwise secure system can be compromised easily if the system or application software on it, or on a linked system, has vulnerabilities. Therefore, it is critical that software on networked computer systems be free from security vulnerabilities. Security, vulnerabilities in software arise from a number of development factors; but these vulnerabilities can generally be traced to poor software development practices, new modes of attacks, mis-configurations, and unsecured links between systems. A Software security assessment instrument can aid in providing a greater level of assurance that software is not exposed to vulnerabilities as a result of defective software requirements, designs, code or exposures due to code complexity, and integration with other applications that are network aware. This paper presents research on the generation of a software security assessment instrument to aid developers in assessing and assuring the security of software in the development and maintenance lifecycles. The research presented here is available at: http://security.jpl.nasa.gov/rssr.
引用
收藏
页码:36 / 42
页数:7
相关论文
共 50 条
  • [31] An Interprofessional Approach to Reducing the Risk of Falls Through Enhanced Collaborative Practice
    Eckstrom, Elizabeth
    Neal, Margaret B.
    Cotrell, Vicki
    Casey, Colleen M.
    McKenzie, Glenise
    Morgove, Megan W.
    DeLander, Gary E.
    Simonson, William
    Lasater, Kathie
    JOURNAL OF THE AMERICAN GERIATRICS SOCIETY, 2016, 64 (08) : 1701 - 1707
  • [32] An Integrated Cyber Security Risk Management Approach for a Cyber-Physical System
    Kure, Halima Ibrahim
    Islam, Shareeful
    Razzaque, Mohammad Abdur
    APPLIED SCIENCES-BASEL, 2018, 8 (06):
  • [33] Reducing security risk for transportation management centers
    Rowshan, S
    Sauntry, WC
    Wood, TM
    Churchill, B
    Levine, SR
    SECURITY, 2005, (1938): : 17 - 24
  • [34] Software diversity as a measure for reducing development risk
    Popov, Peter
    Povyakalo, Andrey
    Stankovic, Vladimir
    Strigini, Lorenzo
    2014 TENTH EUROPEAN DEPENDABLE COMPUTING CONFERENCE (EDCC), 2014, : 106 - 117
  • [35] Integrated risk management: Techniques and strategies for reducing risk
    Scordis, NA
    JOURNAL OF RISK AND INSURANCE, 2000, 67 (04) : 667 - 670
  • [36] An integrated model of risk and risk-reducing strategies
    Cho, J
    Lee, J
    JOURNAL OF BUSINESS RESEARCH, 2006, 59 (01) : 112 - 120
  • [37] An integrated approach to rail passenger security
    Traffic Eng. Control, 2008, 8 (291-292):
  • [38] An integrated approach to security incident management
    DFLabs, Italy
    Netw. Secur., 2008, 2 (14-16):
  • [39] Integrated Approach to Software Defect Prediction
    Felix, Ebubeogu Amarachukwu
    Lee, Sai Peck
    IEEE ACCESS, 2017, 5 : 21524 - 21547
  • [40] Corporate Security Requires an Integrated Approach
    Roney, Michael
    FORBES, 2014, 193 (05): : 58 - +