首页> 外文学位 >Towards a Secure Software Development Framework Based on an Integrated Engineering Process.
【24h】

Towards a Secure Software Development Framework Based on an Integrated Engineering Process.

机译:迈向基于集成工程流程的安全软件开发框架。

获取原文
获取原文并翻译 | 示例

摘要

The rapid growth of communication and globalization has changed the software engineering process. Security has become a crucial component of any software system. However, software security development is still a maturing process; software developers often lack the knowledge and skills needed to develop secure software. Clearly, designing software with security in mind will produce a more secure architectural design and eventually more secure software, yet it is still unclear how to evaluate and conduct this intuitive process. The creation of secure software requires more than simply mandating the use of a secure software development lifecycle; the components produced by each stage of the lifecycle must be correctly implemented for the resulting system to achieve its intended goals.;This research discusses the software engineering process to develop secure software, through a form of 'development framework', and demonstrates that a more effective approach to the development of secure software can result from the integration of carefully selected security patterns into appropriate stages of the software development lifecycle to ensure that security designs are correctly implemented. Hence, the framework enables developers with limited security experience to more easily and more reliably develop secure software.;In addition, more than sixty percent of the reported---high risk---software vulnerabilities are due to design flaws. Nevertheless, the majority of these flaws can be avoided if they have been discovered early enough. Therefore, this research proposes security evaluation strategies that are effective in discovering potential security threats at early stages of the development process with the goals of providing designed-in countermeasures and minimizing the cost of the development process dramatically.
机译:通信和全球化的迅速发展改变了软件工程过程。安全性已成为任何软件系统的重要组成部分。但是,软件安全性开发仍是一个成熟的过程。软件开发人员通常缺乏开发安全软件所需的知识和技能。显然,在设计软件时要考虑安全性,这将产生更安全的体系结构设计,最终会产生更安全的软件,但仍不清楚如何评估和执行这一直观过程。创建安全软件不仅需要简单地强制使用安全软件开发生命周期,还需要更多。必须正确实施生命周期每个阶段产生的组件,以使最终系统达到其预期目标。;本研究讨论了通过“开发框架”形式开发安全软件的软件工程过程,并证明了更多将精心选择的安全模式集成到软件开发生命周期的适当阶段,可以确保安全设计的正确实施,从而可以有效地开发安全软件。因此,该框架使具有有限安全经验的开发人员可以更轻松,更可靠地开发安全软件。此外,报告的高风险软件漏洞中有60%以上是设计缺陷造成的。但是,如果能够尽早发现这些缺陷,则可以避免大多数缺陷。因此,本研究提出了一种安全评估策略,可以有效地在开发过程的早期阶段发现潜在的安全威胁,其目的是提供设计对策并显着降低开发过程的成本。

著录项

  • 作者

    Alkussayer, Abdulaziz.;

  • 作者单位

    Florida Institute of Technology.;

  • 授予单位 Florida Institute of Technology.;
  • 学科 Computer Science.
  • 学位 Ph.D.
  • 年度 2011
  • 页码 151 p.
  • 总页数 151
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 农学(农艺学);
  • 关键词

  • 入库时间 2022-08-17 11:44:22

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号