Security Engineering towards Building a Secure Software

نویسندگان

  • Mohammad Nazmul Alam
  • Subhra Prosun Paul
  • Shahrin Chowdhury
  • Premkumar T. Devanbu
چکیده

Information Systems Security is one of the most critical challenges presently facing nearly every one of the organizations. However, making certain security and quality in both information and the systems which control information is a difficult goal necessitating the mixture of two wide research disciplines which are typically separate: security engineering and secure software engineering. Security engineering has an extensive history, and has focused generally on providing advances in security models, techniques and protocols, but it remains in a steady state of the development. Secure software engineering, however, has emerged relatively recently, but is growing quickly and is paying attention on the integration of security into software engineering techniques; models and processes, in order to build up more secure information systems. In the study of security engineering, security described as the protection from harm. It presented the principles of security, the number of security mechanisms and the risk analysis to identify the risk. In the study of secure software engineering, it has been identified a number of challenges that need to establish for developing the secure software system. We also investigated a number of methods and languages that is modeling the security into software systems.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Towards Building Secure Software Systems

Software security breaches are now very extremely common and a larger percentage is caused by software design defects. Since individuals and organizations now completely depend on software systems for their day-to-day operations, it is then important to produce secure software products. This paper discusses the problems of producing secure software products and provides a model for improving so...

متن کامل

The ISDF Framework: Towards Secure Software Development

The rapid growth of communication and globalization has changed the software engineering process. Security has become a crucial component of any software system. However, software developers often lack the knowledge and skills needed to develop secure software. Clearly, the creation of secure software requires more than simply mandating the use of a secure software development lifecycle; the co...

متن کامل

Curriculum for Modeling Security: Experiences and Lessons Learned

The need to develop secure software systems is well recognized by academics and industrialists alike. Current software systems contain sensitive information and therefore it is important that considerable efforts are made to secure such information. To improve the security of software systems, recent research has identified that security analysis should be integrated into software engineering t...

متن کامل

Building secure-by-construction distributed component-based systems

We present an automated method to build secure distributed systems from an abstract multilevel security component-based model. We take as input a high-level secureBIP componentbased model and transform it into a decentralized Send/Receive secureBIP model and further on distributed code. The security policy is defined at the design time. Information flow policy is verified and automatically pres...

متن کامل

Towards a Systematic Development of Secure Systems

In this paper we outline a new process model for security engineering. This process model extends object oriented, use case driven software development by the systematic treatment of security related issues. We introduce the notion of security aspects describing security relevant requirements and measures at a certain level of abstraction. We define a micro-process for security analysis support...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2013