Swinburne
Browse

Assessing security properties of software components: A software engineer's perspective

Download (200.57 kB)
conference contribution
posted on 2024-07-11, 12:23 authored by Khaled M. Khan, Jun HanJun Han
The paper proposes an assessment scheme for the security properties of software components. The proposed scheme consists of three stages: (i) a system-specific security requirement specification of the enclosing application; (ii) a component-specific security rating; and (iii) an evaluation method for the scored security properties of the candidate component. The assessment scheme ultimately provides a numeric score indicating a relative strength of the security properties of the candidate component. The scheme is partially based on ISO/IEC 15408, the Common Criteria for Information Technology Security Evaluation (CC) and the Multi-Element Component Comparison and Analysis (MECCA) model. The scheme is flexible enough for software engineers to use. in order to get a first-hand preliminary assessment of the security posture of candidate components.

History

Available versions

PDF (Published version)

ISBN

769525512

Journal title

Proceedings of the Australian Software Engineering Conference, ASWEC

Conference name

The Australian Software Engineering Conference, ASWEC

Volume

2006

Pagination

9 pp

Publisher

IEEE

Copyright statement

Copyright © 2006 IEEE. The published version is reproduced in accordance with the copyright policy of the publisher. Personal use of this material is permitted. However, permission to reprint/republish this material for advertising or promotional purposes or for creating new collective works for resale or redistribution to servers or lists, or to reuse any copyrighted component of this work in oTher works must be obtained from The IEEE.

Language

eng

Usage metrics

    Publications

    Categories

    No categories selected

    Keywords

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC