Incorporating Security into Software Development Process

被引:0
|
作者
Yoshioka, R. [1 ]
Watanobe, Y. [1 ]
Mirenkov, N. [1 ]
机构
[1] Univ Aizu, Aizu Wakamatsu, Fukushima, Japan
关键词
D O I
10.3233/978-1-58603-916-5-99
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
A general scheme of software development process is considered and some aspects related to integrating security into this scheme are analyzed. In particular, semantic-based, defense-in-depth techniques embedded into system/component defense shields and data acquiring/monitoring kernels are considered. The defense shields are to semantically check data of every input before a software component may process them and also to check every output before sending it to other components. The kernels are to regularly perform semantic analysis of the internal status and local data of a component/system. Based on these two ideas, real-time discovery of Vulnerabilities and threats is possible even when various protective measures, such as, passwords, firewalls, intrusion detection systems, access control lists, etc. have been breached. Existing programming systems and possible new methods to realize the shields and kernels are also considered.
引用
收藏
页码:99 / 109
页数:11
相关论文
共 50 条
  • [31] A case study in applying common criteria to development process to improve security of software products
    Kim, SH
    Leem, CS
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2004, PT 1, 2004, 3043 : 1069 - 1077
  • [32] A Novel Security-Enhanced Agile Software Development Process Applied in an Industrial Setting
    Baca, Dejan
    Boldt, Martin
    Carlsson, Bengt
    Jacobsson, Andreas
    PROCEEDINGS 10TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY ARES 2015, 2015, : 11 - 19
  • [33] Incorporating price sensitivity measurement into the software engineering process
    Harmon, R
    Raffo, D
    Faulk, S
    TECHNOLOGY MANAGEMENT FOR RESHAPING THE WORLD, 2003, : 316 - 323
  • [34] Human Aspects and Security in Software Development
    Staron, Miroslaw
    Abrahao, Silvia
    Penzenstaler, Birgit
    Serebrenik, Alexander
    IEEE SOFTWARE, 2024, 41 (04) : 171 - 174
  • [35] Integrating Security Concerns into Software Development
    Al-Fedaghi, Sabah
    Al-Kanderi, Fajer
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2013, 7 (03): : 235 - 247
  • [36] Integrating security and privacy in software development
    Baldassarre, Maria Teresa
    Barletta, Vita Santa
    Caivano, Danilo
    Scalera, Michele
    SOFTWARE QUALITY JOURNAL, 2020, 28 (03) : 987 - 1018
  • [37] Security enforcement aware software development
    Vanoverberghe, Dries
    Piessens, Frank
    INFORMATION AND SOFTWARE TECHNOLOGY, 2009, 51 (07) : 1172 - 1185
  • [38] Integrating security concerns into software development
    Al-Fedaghi, S. (sabah@alfedaghi.com), 1600, Science and Engineering Research Support Society, 20 Virginia Court, Sandy Bay, Tasmania, Australia (07):
  • [39] Integrating Application Security into Software Development
    Payne, Jeffery
    IT PROFESSIONAL, 2010, 12 (02) : 6 - 9
  • [40] Software development and related security issues
    Zadeh, Jeff
    DeVolder, Dennis
    PROCEEDINGS IEEE SOUTHEASTCON 2007, VOLS 1 AND 2, 2007, : 746 - +