计算机科学
计算机安全
软件安全保证
钥匙(锁)
背景(考古学)
安全性测试
威胁模型
软件
安全信息和事件管理
信息安全
软件工程
保安服务
云安全计算
云计算
古生物学
程序设计语言
生物
操作系统
作者
Katja Tuma,Laurens Sion,Riccardo Scandariato,Koen Yskout
标识
DOI:10.1145/3365438.3410954
摘要
Security by design is a key principle for realizing secure software systems and it is advised to hunt for security flaws from the very early stages of development. At design-time, security analysis is often performed manually by means of either threat modeling or expert-based design inspections. However, when leveraging the wide range of established knowledge bases on security design flaws (e.g., CWE, CAWE), these manual assessments become too time consuming, error-prone, and infeasible in the context of contemporary development practices with frequent iterations. This paper focuses on design inspection and explores the potential for automating the application of inspection rules to speed up the security analysis.
科研通智能强力驱动
Strongly Powered by AbleSci AI