arrow
返回

Detecting Software Security Vulnerabilities Via Requirements Dependency Analysis

delete2022-05-01
delete24
delete
OA
AI
W
Wentao Wang
F
Faryn Dumont
N
Nan Niu *
G
Glen Horton
DOI:10.1109/TSE.2020.3030745delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
Cyber attacks targeting software applications have a tremendous impact on our daily life. For example, attackers have utilized vulnerabilities of web applications to steal and gain unauthorized use of sensitive data stored in these systems. Previous studies indicate that security testing is highly precise, and therefore is widely applied to validate individual security requirements. However, dependencies between security requirements may cause additional vulnerabilities. Manual dependency detection faces scalability challenges, e.g., a previous study shows that the pairwise dependency analysis of 40 requirements would take around 12 hours. In this article, we present a novel approach which integrates the interdependency among high-level security requirements, such as those documented in policies, regulations, and standards. We then use automated requirements tracing methods to identify product-level security requirements and their dependencies. Our manual analysis of HIPAA and FIPS 200 leads to the identification of five types of high-level security requirements dependencies, which further inform the automated tracing methods and guide the designs of system-level security tests. Experimental results on five projects in healthcare and education domains show the significant recall improvements at 81 percent. Our case study on a deployed production system uncovers four previously unknown vulnerabilities by using the detected requirements dependencies as test paths, demonstrating our approach's value in connecting requirements engineering with security testing.
Keyword:
Security
Software
Testing
Manuals
Static analysis
Regulation
Scalability
Security requirements
requirements dependency management
requirements traceability
vulnerability discovery
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

IEEE Transactions on Software Engineering 封面图
IEEE Transactions on Software Engineering
IF:
5.6
论文数:
2.8K
被引数:
1.1W

机构

U
University System of Ohio
学者数:
15.4W
论文数: 13.0W
被引数: 200
U
University of Cincinnati
学者数:
1.8W
论文数: 1.4W
被引数: 2.2W
引用论文

引用论文

Fabrication of Adhesive Substrate for Incorporating Hydrogels to Investigate the Influence of Stiffness on Cancer Cell Behavior
err2020-08-20
err0
PREAI
errGenaro Vázquez-Victorio; Adriana Rodríguez-Hernández; Mariel Cano-Jorge; Ana Ximena Monroy-Romero; Marina Macías-Silva; Mathieu Hautefeuille
err分享
err收藏
err分享
err收藏
Vulnerability Discovery with Attack Injection带有攻击注入的漏洞发现
err2010-05-01
err40
PREAI
errAntunes, Joao; Neves, Nuno; Correia, Miguel; Verissimo, Paulo; Neves, Rui
err分享
err收藏
Strong-coupling Bose polarons in a Bose-Einstein condensate
err2017-07-06
err0
errOAAI
errF. Grusdt; R. Schmidt; Y. E. Shchadilova; E. Demler
err分享
err收藏
Deep space instrument design for thermal infrared imaging with MERTIS
err2011-09-08
err0
PREAI
errI. Walter; T. Zeh; J. Helbert; H. Hiesinger; A. Gebhardt; H. Hirsch; J. Knollenberg; E. Kessler; M. Rataj; J. Habermeier; S. Kaiser; G. Peter
err分享
err收藏
Enhanced electrochemical heavy metal ion sensor using liquid metal marbles - towards on-chip application
err2012-12-01
err0
PREAI
errV. Sivan; S. Y. Tang; A. P. O'Mullane; P. Petersen; N. Eshtiaghi; K. Kalantar-zadeh; A. Mitchell
err分享
err收藏
Formation of coronene:water complexes: FTIR study in argon matrices and theoretical characterisation
err2017-01-01
err0
PREAI
errA. Simon; J. A. Noble; G. Rouaut; A. Moudens; C. Aupetit; C. Iftner; J. Mascetti
err分享
err收藏
Efficacy of different dynamic functional connectivity methods to capture cognitively relevant information
err2019-03-01
err0
errOAAI
errHua Xie; Charles Y. Zheng; Daniel A. Handwerker; Peter A. Bandettini; Vince D. Calhoun; Sunanda Mitra; Javier Gonzalez-Castillo
err分享
err收藏
学者 查看更多内容