[Paper Review] STORE: Security Threat Oriented Requirements Engineering Methodology
This paper proposes STORE (Security Threat Oriented Requirements Engineering), a methodology that enhances early security requirement elicitation by systematically analyzing threats through four attack perspective points: Point of Attack (PoA), Point of Breakdown (PoB), Point of Compromise (PoC), and Point of Detection (PoD). The approach improves systematic and organized identification of security requirements, validated via an ERP system case study and shown to outperform SQUARE and MOSRE in effectiveness and efficiency.
As we are continuously depending on information technology applications by adopting electronic channels and software applications for our business, online transaction and communication, software security is increasingly becoming a necessity and more advanced concern. Both the functional and non-functional requirements are important and provide the necessary needs at the early phases of the software development process, specifically in the requirement phase. The aim of this research is to identify security threats early in the software development process to help the requirement engineer elicit appropriate security requirements in a more systematic manner throughout the requirement engineering process to ensure a secure and quality software development. This article proposes the STORE methodology for security requirement elicitation based on security threats analysis, which includes the identification of four points: PoA, PoB, PoC and PoD for effective security attack analysis. Further, the proposed STORE methodology is also validated by a case study of an ERP System. We also compare our STORE methodology with two existing techniques, namely, SQUARE and MOSRE. We have shown that more effective and efficient security requirements can be elicited by the STORE methodology and that it helps the security requirement engineer to elicit security requirements in a more organized manner.
Motivation & Objective
- To address the growing need for early identification of security threats in software development to ensure secure and high-quality systems.
- To improve the systematic elicitation of security requirements during the requirement engineering phase.
- To provide a structured methodology that supports security requirement engineers in identifying and analyzing potential threats more effectively.
- To validate the proposed methodology against existing approaches like SQUARE and MOSRE in a real-world context.
Proposed method
- The STORE methodology introduces four key perspectives—Point of Attack (PoA), Point of Breakdown (PoB), Point of Compromise (PoC), and Point of Detection (PoD)—to guide systematic threat analysis.
- Each perspective helps identify specific aspects of potential security threats: PoA identifies where attacks may originate, PoB where system weaknesses may exist, PoC where data or functionality may be compromised, and PoD where detection mechanisms can be implemented.
- The methodology integrates threat modeling into the requirement engineering process, enabling security requirements to be elicited in a structured and traceable manner.
- It employs a threat analysis framework that maps security threats to specific system components and requirements, enhancing traceability and completeness.
- The approach is applied in a case study on an ERP system to demonstrate practical applicability and effectiveness.
- The methodology is compared with two established techniques—SQUARE and MOSRE—using qualitative and comparative analysis to evaluate its performance.
Experimental results
Research questions
- RQ1How can security threats be systematically identified and analyzed during the early phases of software development?
- RQ2To what extent does the STORE methodology improve the organization and completeness of elicited security requirements compared to existing methods?
- RQ3How does the integration of PoA, PoB, PoC, and PoD perspectives enhance threat modeling and requirement elicitation?
- RQ4What evidence supports the effectiveness and efficiency of STORE in real-world system development, such as in an ERP context?
- RQ5How does STORE compare in performance and usability to established methodologies like SQUARE and MOSRE?
Key findings
- The STORE methodology enables more effective and efficient elicitation of security requirements compared to existing approaches like SQUARE and MOSRE.
- The case study on an ERP system demonstrated that STORE supports a more organized and comprehensive identification of security threats and corresponding requirements.
- The use of PoA, PoB, PoC, and PoD perspectives significantly improves the traceability and systematic analysis of potential attack vectors.
- The methodology enhances the ability of requirement engineers to anticipate and address security issues earlier in the development lifecycle.
- Quantitative and qualitative comparisons with SQUARE and MOSRE indicate that STORE provides better structure and clarity in threat and requirement modeling.
- The validation confirms that STORE supports a more systematic and repeatable process for security requirement engineering in complex systems.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.