arrow
返回

Automated Risk Management Based Software Security Vulnerabilities Management

delete2022-01-01
delete8
delete
OA
AI
R
Raghavendra Rao Althar
D
Debabrata Samanta
M
Manjit Kaur
D
Dilbag Singh
H
Heung-No Lee *
DOI:10.1109/ACCESS.2022.3185069delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
An automated risk assessment approach is explored in this work. The focus is to optimize the conventional threat modeling approach to explore software system vulnerabilities. Data produced in the software development processes are better leveraged using Machine Learning approaches. A large amount of industry knowledge around security vulnerabilities can be leveraged to enhance current threat modeling approaches. Work done here is in the ecosystem of software development processes that use Agile methodology. Insurance business domain data are explored as a target for this study. The focus is to enhance the traditional threat modeling approach with a better quantitative approach and reduce the biases introduced by the people who are part of software development processes. This effort will help bridge multiple data sources prevalent across the software development ecosystem. Bringing these various data sources together will assist in understanding patterns associated with security aspects of the software systems. This perspective further helps to understand and devise better controls. Approaches explored so far have considered individual areas of software development and their influence on improving security. There is a need to build an integrated approach for a total security solution for the software systems. A wide variety of machine learning approaches and ensemble approaches will be explored. The insurance business domain is considered for the research here. CWE (Common Weaknesses Enumeration) mapping from industry knowledge are leveraged to validate the security needs from the industry perspective. This combination of industry and company data will help get a holistic picture of the software system's security. Combining the industry and company data helps lay down the path for an integrated security management system in software development. The risk management framework with the quantitative threat modeling process is the work's uniqueness. This work contributes toward making the software systems secure and robust with time.
Keyword:
Software
Security
Industries
Software systems
Data models
Risk management
Computer crime
Quantitative threat modeling
software security
machine learning
quantitative risk assessment
integrated security management system

期刊

IEEE Access 封面图
IEEE Access
IF:
3.6
论文数:
9.8W
被引数:
29.4W

机构

C
christ university
学者数:
1.7K
论文数: 1.3K
被引数: 5
引用论文

引用论文

Short-Term Effects of Cattle Browsing on Tree Sapling Growth in Mountain Wooded Pastures
err2006-06-09
err0
PREAI
errCharlotte Vandenberghe; François Freléchoux; Marie-Agnès Moravie; Fawziah Gadallah; Alexandre Buttler
err分享
err收藏
Genesis of corrugated fault surfaces by strain localization recorded at oceanic detachments
err2018-09-01
err0
errOAAI
errRoss Parnell-Turner; Javier Escartín; Jean-Arthur Olive; Deborah K. Smith; Sven Petersen
err分享
err收藏
Engineering Security Vulnerability Prevention, Detection, and Response
err2018-09-01
err33
PREAI
errWilliams, Laurie; McGraw, Gary; Migues, Sammy
err分享
err收藏
Toward Empirically Investigating Non-Functional Requirements of iOS Developers on Stack Overflow
err2019-01-01
err16
errOAAI
errAhmad, Arshad; Feng, Chong; Li, Kan; Asim, Syed Mohammad; Sun, Tingting
err分享
err收藏
学者 查看更多内容