A vulnerability-centric requirements engineering framework: analyzing security attacks, countermeasures, and requirements based on vulnerabilities

被引:0
|
作者
Golnaz Elahi
Eric Yu
Nicola Zannone
机构
[1] University of Toronto,
来源
Requirements Engineering | 2010年 / 15卷
关键词
Security requirements engineering; Risk analysis; Agent-oriented software engineering; Empirical security knowledge;
D O I
暂无
中图分类号
学科分类号
摘要
Many security breaches occur because of exploitation of vulnerabilities within the system. Vulnerabilities are weaknesses in the requirements, design, and implementation, which attackers exploit to compromise the system. This paper proposes a methodological framework for security requirements elicitation and analysis centered on vulnerabilities. The framework offers modeling and analysis facilities to assist system designers in analyzing vulnerabilities and their effects on the system; identifying potential attackers and analyzing their behavior for compromising the system; and identifying and analyzing the countermeasures to protect the system. The framework proposes a qualitative goal model evaluation analysis for assessing the risks of vulnerabilities exploitation and analyzing the impact of countermeasures on such risks.
引用
收藏
页码:41 / 62
页数:21
相关论文
共 50 条
  • [41] A goal-driven and agent-based requirements engineering framework*
    Paolo Donzelli
    Requirements Engineering, 2004, 9 : 16 - 39
  • [42] Security Requirements Engineering (SRE) Framework for Cyber-Physical Systems (CPS): SRE for CPS
    ur Rehman, Shafiq
    Gruhn, Volker
    NEW TRENDS IN INTELLIGENT SOFTWARE METHODOLOGIES, TOOLS AND TECHNIQUES, 2017, 297 : 153 - 163
  • [43] Social Engineering Based Security Requirements Elicitation Model for Advanced Persistent Threats
    Kim, Seung-Jun
    Lee, Seok-Won
    REQUIREMENTS ENGINEERING FOR INTERNET OF THINGS, 2018, 809 : 29 - 40
  • [44] E-SCORE: A web-based tool for security requirements engineering
    Hnaini, Hiba
    Mazo, Raul
    Champeau, Joel
    Vallejo, Paola
    Galindo, Jose
    SOFTWAREX, 2024, 26
  • [45] Challenges and research directions for heterogeneous cyber-physical system based on IEC 61850: Vulnerabilities, security requirements, and security architecture
    Yoo, Hyunguk
    Shon, Taeshik
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2016, 61 : 128 - 136
  • [46] MIRA: A Tooling-Framework to Experiment with Model-Based Requirements Engineering
    Teufl, Sabine
    Mou, Dongyue
    Ratiu, Daniel
    2013 21ST IEEE INTERNATIONAL REQUIREMENTS ENGINEERING CONFERENCE (RE), 2013, : 330 - 331
  • [47] SENSE: A Flow-Down Semantics-Based Requirements Engineering Framework
    Kravari, Kalliopi
    Antoniou, Christina
    Bassiliades, Nick
    ALGORITHMS, 2021, 14 (10)
  • [48] The Requirements Engineering Framework Based On ISO 29148:2011 and Multi-View Modeling Framework
    Selvyanti, Debby
    Bandung, Yoanes
    2017 4TH INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY SYSTEMS AND INNOVATION (ICITSI), 2017, : 128 - 133
  • [49] Towards Scenario-Based Security Requirements Engineering for Cyber-Physical Systems
    Koch, Thorsten
    SOFTWARE TECHNOLOGIES: APPLICATIONS AND FOUNDATIONS, 2018, 11176 : 633 - 643
  • [50] A common criteria based security requirements engineering process for the development of secure information systems
    Mellado, Daniel
    Fernandez-Medina, Eduardo
    Piattini, Mario
    COMPUTER STANDARDS & INTERFACES, 2007, 29 (02) : 244 - 253