conference-paper
Automating the early detection of security design flaws
Research footprint
At a glance
- الاستشهادات
- 40
- المراجع
- 24
- Comments
- 0
Paper overview
Abstract
Security by design is a key principle for realizing secure software systems and it is advised to hunt for security flaws from the very early stages of development. At design-time, security analysis is often performed manually by means of either threat modeling or expert-based design inspections. However, when leveraging the wide range of established knowledge bases on security design flaws (e.g., CWE, CAWE), these manual assessments become too time consuming, error-prone, and infeasible in the context of contemporary development practices with frequent iterations. This paper focuses on design inspection and explores the potential for automating the application of inspection rules to speed up the security analysis.
Record transparency
Publication details
- DOI
- 10.1145/3365438.3410954
- OpenAlex
- W3091426345
- Document type
- conference-paper
- Language
- EN
- Last metadata update
Comments
تسجيل الدخول للانضمام إلى النقاش.