[论文解读] STORE: Security Threat Oriented Requirements Engineering Methodology
本文提出 STORE(安全威胁导向的需求工程)方法,通过四个攻击视角点——攻击点(PoA)、崩溃点(PoB)、妥协点(PoC)和检测点(PoD)——系统性地分析威胁,以增强早期安全需求的获取。该方法提升了安全需求识别的系统性和条理性,在一个ERP系统案例研究中得到验证,且在有效性和效率方面优于SQUARE和MOSRE。
As we are continuously depending on information technology applications by adopting electronic channels and software applications for our business, online transaction and communication, software security is increasingly becoming a necessity and more advanced concern. Both the functional and non-functional requirements are important and provide the necessary needs at the early phases of the software development process, specifically in the requirement phase. The aim of this research is to identify security threats early in the software development process to help the requirement engineer elicit appropriate security requirements in a more systematic manner throughout the requirement engineering process to ensure a secure and quality software development. This article proposes the STORE methodology for security requirement elicitation based on security threats analysis, which includes the identification of four points: PoA, PoB, PoC and PoD for effective security attack analysis. Further, the proposed STORE methodology is also validated by a case study of an ERP System. We also compare our STORE methodology with two existing techniques, namely, SQUARE and MOSRE. We have shown that more effective and efficient security requirements can be elicited by the STORE methodology and that it helps the security requirement engineer to elicit security requirements in a more organized manner.
研究动机与目标
- 为应对软件开发中早期识别安全威胁的日益增长需求,以确保系统安全且高质量。
- 改进需求工程阶段中安全需求的系统性获取。
- 提供一种结构化方法,支持安全需求工程师更有效地识别和分析潜在威胁。
- 在真实世界环境中,将所提方法与SQUARE和MOSRE等现有方法进行对比验证。
提出的方法
- STORE方法引入四个关键视角——攻击点(PoA)、崩溃点(PoB)、妥协点(PoC)和检测点(PoD),以指导系统化的威胁分析。
- 每个视角有助于识别潜在安全威胁的特定方面:PoA识别攻击可能的来源,PoB识别系统弱点可能存在的位置,PoC识别数据或功能可能被破坏的位置,PoD识别可实施检测机制的位置。
- 该方法将威胁建模整合到需求工程过程中,使安全需求能够以结构化且可追溯的方式被获取。
- 它采用一种威胁分析框架,将安全威胁映射到特定系统组件和需求,从而增强可追溯性和完整性。
- 该方法在ERP系统的案例研究中应用,以展示其在实际场景中的适用性和有效性。
- 通过定性和对比分析,将该方法与两种成熟技术——SQUARE和MOSRE——进行比较,以评估其性能。
实验结果
研究问题
- RQ1如何在软件开发的早期阶段系统性地识别和分析安全威胁?
- RQ2与现有方法相比,STORE方法在组织性和完整性方面,对所获取安全需求的提升程度如何?
- RQ3PoA、PoB、PoC和PoD视角的整合如何增强威胁建模和需求获取?
- RQ4有哪些证据支持STORE在真实世界系统开发(如ERP环境)中的有效性和高效性?
- RQ5与SQUARE和MOSRE等成熟方法相比,STORE在性能和可用性方面表现如何?
主要发现
- 与SQUARE和MOSRE等现有方法相比,STORE方法在安全需求获取方面表现出更高的有效性和效率。
- ERP系统案例研究显示,STORE支持对安全威胁及其对应需求进行更系统化和全面的识别。
- 使用PoA、PoB、PoC和PoD视角显著提升了对潜在攻击向量的可追溯性和系统性分析能力。
- 该方法增强了需求工程师在开发生命周期早期预见并解决安全问题的能力。
- 与SQUARE和MOSRE的定量和定性比较表明,STORE在威胁和需求建模方面提供了更优的结构和清晰度。
- 验证结果确认,STORE支持在复杂系统中进行更系统化和可重复的安全需求工程流程。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。