Cristin-resultat-ID: 1678550
Sist endret: 14. februar 2020, 12:18
NVI-rapporteringsår: 2019
Resultat
Vitenskapelig Kapittel/Artikkel/Konferanseartikkel
2019

An Evaluation of a Test-Driven Security Risk Analysis Approach Based on Two Industrial Case Studies

Bidragsytere:
  • Gencer Erdogan
  • Phu Hong Nguyen
  • Fredrik Seehusen
  • Ketil Stølen
  • Jon Hofstad og
  • Jan Øyvind Aagedal

Bok

Om resultatet

Vitenskapelig Kapittel/Artikkel/Konferanseartikkel
Publiseringsår: 2019
Sider: 69 - 103
ISBN:
  • 9781522563136

Klassifisering

Fagfelt (NPI)

Fagfelt: IKT
- Fagområde: Realfag og teknologi

Beskrivelse Beskrivelse

Tittel

An Evaluation of a Test-Driven Security Risk Analysis Approach Based on Two Industrial Case Studies

Sammendrag

Risk-driven testing and test-driven risk assessment are two strongly related approaches, though the latter is less explored. This chapter presents an evaluation of a test-driven security risk assessment approach to assess how useful testing is for validating and correcting security risk models. Based on the guidelines for case study research, two industrial case studies were analyzed: a multilingual financial web application and a mobile financial application. In both case studies, the testing yielded new information, which was not found in the risk assessment phase. In the first case study, new vulnerabilities were found that resulted in an update of the likelihood values of threat scenarios and risks in the risk model. New vulnerabilities were also identified and added to the risk model in the second case study. These updates led to more accurate risk models, which indicate that the testing was indeed useful for validating and correcting the risk models.

Bidragsytere

Gencer Erdogan

  • Tilknyttet:
    Forfatter
    ved Sustainable Communication Technologies ved SINTEF AS
Aktiv cristin-person

Phu Hong Nguyen

  • Tilknyttet:
    Forfatter
    ved Sustainable Communication Technologies ved SINTEF AS

Fredrik Seehusen

  • Tilknyttet:
    Forfatter
    ved Sustainable Communication Technologies ved SINTEF AS

Ketil Stølen

  • Tilknyttet:
    Forfatter
    ved Sustainable Communication Technologies ved SINTEF AS

Jon Hofstad

  • Tilknyttet:
    Forfatter
    ved Diverse norske bedrifter og organisasjoner
1 - 5 av 6 | Neste | Siste »

Resultatet er en del av Resultatet er en del av

Exploring Security in Software Architecture and Design.

Felderer, Michael; Scandariato, Riccardo. 2019, IGI Global. LUI, CthVitenskapelig antologi/Konferanseserie
1 - 1 av 1