Assessment of Risk Perception in Security Requirements Composition

被引:0
|
作者
Hibshi, Hanan [1 ,2 ]
Breaux, Travis D. [1 ]
Broomell, Stephen B. [3 ]
机构
[1] Carnegie Mellon Univ, Inst Software Res, Pittsburgh, PA 15213 USA
[2] King Abdulaziz Univ, Coll Comp, Jeddah, Saudi Arabia
[3] Carnegie Mellon Univ, Dept Social & Decis Sci, Pittsburgh, PA 15213 USA
关键词
user study; vignettes; factor surveys; security requirements; requirements elicitation;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Security requirements analysis depends on how well-trained analysts perceive security risk, understand the impact of various vulnerabilities, and mitigate threats. When systems are composed of multiple machines, configurations, and software components that interact with each other, risk perception must account for the composition of security requirements. In this paper, we report on how changes to security requirements affect analysts risk perceptions and their decisions about how to modify the requirements to reach adequate security levels. We conducted two user surveys of 174 participants wherein participants assess security levels across 64 factorial vignettes. We analyzed the survey results using multi-level modeling to test for the effect of security requirements composition on participants' overall security adequacy ratings and on their ratings of individual requirements. We accompanied this analysis with grounded analysis of elicited requirements aimed at lowering the security risk. Our results suggest that requirements composition affects experts' adequacy ratings on security requirements. In addition, we identified three categories of requirements modifications, called refinements, replacements and reinforcements, and we measured how these categories compare with overall perceived security risk. Finally, we discuss the future impact of our work in security requirements assessment practice.
引用
收藏
页码:146 / 155
页数:10
相关论文
共 50 条
  • [31] Security risk and its perception in the eyes of the Czech public
    Buriánek, J
    SOCIOLOGICKY CASOPIS-CZECH SOCIOLOGICAL REVIEW, 2001, 37 (01): : 43 - 64
  • [32] Incentive Alignment and Risk Perception: An Information Security Application
    Farahmand, Fariborz
    Atallah, Mikhail J.
    Spafford, Eugene H.
    IEEE TRANSACTIONS ON ENGINEERING MANAGEMENT, 2013, 60 (02) : 238 - 246
  • [33] Risk perception and resource security for female agricultural workers
    Snyder, K
    SOCIOECONOMIC ASPECTS OF HUMAN BEHAVIORAL ECOLOGY, 2004, 23 : 271 - 292
  • [34] Difference in risk perception of onboard security threats by aircrew and aviation security experts
    Derrickson, William
    Tripathi, Kartikeya
    TRANSPORTATION RESEARCH INTERDISCIPLINARY PERSPECTIVES, 2022, 16
  • [35] Security Risk Assessment: Towards a Justification for the Security Risk Factor Table Model
    Rivera, Beverly
    Zapata, Francisco
    Kreinovich, Vladik
    JOURNAL OF ADVANCED COMPUTATIONAL INTELLIGENCE AND INTELLIGENT INFORMATICS, 2015, 19 (05) : 676 - 680
  • [36] Sec-MoSC Tooling - Incorporating Security Requirements into Service Composition
    Souza, Andre R. R.
    Silva, Bruno L. B.
    Lins, Fernando A. A.
    Damasceno, Julio C.
    Rosa, Nelson S.
    Maciel, Paulo R. M.
    Medeiros, Robson W. A.
    Stephenson, Bryan
    Motahari-Nezhad, Hamid R.
    Li, Jun
    Northfleet, Caio
    SERVICE-ORIENTED COMPUTING - ICSOC 2009, PROCEEDINGS, 2009, 5900 : 649 - +
  • [37] Cultural differences in risk perception and assessment
    Kaskutas, LA
    BIRTH DEFECTS RESEARCH PART A-CLINICAL AND MOLECULAR TERATOLOGY, 2006, 76 (05) : 350 - 350
  • [38] Risk perception and assessment of a Brownfield Site
    Sarsby, R. W.
    Karri, Rama Sarma
    Proceedings of the 16th International Conference on Soil Mechanics and Geotechnical Engineering, Vols 1-5: GEOTECHNOLOGY IN HARMONY WITH THE GLOBAL ENVIRONMENT, 2005, : 2437 - 2440
  • [39] THE ASSESSMENT AND PERCEPTION OF RISK - CONCLUDING REMARKS
    WARNER, F
    PROCEEDINGS OF THE ROYAL SOCIETY OF LONDON SERIES A-MATHEMATICAL PHYSICAL AND ENGINEERING SCIENCES, 1981, 376 (1764): : 205 - 206
  • [40] Risk assessment, perception and communication for GMOs
    Tait, J
    HUMAN EXPOSURE TO PESTICIDE RESIDUES, NATURAL TOXINS AND GMOS: REAL AND PERCEIVED RISKS, 2000, (75): : 69 - 76