Refining Use/Misuse/Mitigation Use Cases for Security Requirements
- 1 College of Business & Information Systems, Dakota State University, Madison, USA
Abstract
We investigate security at the same time as the functional requirements by refining and integrating use, misuse, and mitigation use cases. Security requirements rely on the interactions among normal system execution (use cases), attacks (misuse cases), and necessary security strategies (mitigation use cases), but previous approaches only use a high-level of abstraction. We use refinement to uncover details of each case and the relationships among them before integrating them. We identify and model “includes” and “extends” relationships within each refined case type, and use a condition-driven process that maintains these relationships as refinement continues. We then systematically identify and model “threatens” and “mitigates” relationships to integrate the cases at a detailed level.
- Devanbu, P. and Stubblebine, S. (2000) Software Engineering for Security: A Roadmap. Proceedings of the Conference on The Future of Software Engineering, 227-239.
- Ghosh, A., Howell, C. and Whittaker, J. (2002) Building Software Securely from the Ground Up. IEEE Software, 19, 14-16. http://dx.doi.org/10.1109/MS.2002.976936
- McGraw, G. (2004) Software Security. IEEE Security & Privacy, 1, 32-35.
- Anton, A. and Potts, C. (1998) The Use of Goals to Surface Requirements for Evolving Systems. Proceedings of the 20th International Conference on Software Engineering, Kyoto, 19-25 April 1998, 157-166. http://dx.doi.org/10.1109/ICSE.1998.671112
- Alexander, I. (2002) Initial Industrial Experience of Misuse Cases in Tradeoff Analysis. Proceedings of the 10th Anniversary IEEE Joint International Conference on Requirements Engineering, Essen, 9-13 September 2002, 61-68. http://dx.doi.org/10.1109/ICRE.2002.1048506
- Alexander, I. (2003) Misuse Cases Help to Elicit Non-Functional Requirements. Computing & Control Engineering Journal, 14, 40-45. http://dx.doi.org/10.1049/cce:20030108
- Alexander, I. (2003) Misuse Cases: Use Cases with Hostile Intent. IEEE Software, 20, 58-66. http://dx.doi.org/10.1109/MS.2003.1159030
- Alexander, I. (2002) Modelling the Interplay of Conflicting Goals with Use and Misuse Cases. Proceedings of 8th International Workshop on Requirements Engineering: Foundation for Software Quality (REFSQ’02), Essen, 9-10 September 2002, 145-152.
- Korson, T. (1998) The Misuse of Use Cases (Managing Requirements).
- Pauli, J. and Xu, D. (2005) Misuse Case-Based Design and Analysis of Secure Software Architecture. Proceedings of the International Conference on Information Technology Coding and Computing (ITCC’05), Las Vegas, 4-6 April 2005, 398-403.
- Tohidi, M. (2003) Task Modeling. Directed Studies Research Honors Project. Carleton University, Ottawa.
- Smith, J. (1999) The Estimation of Effort Based on Use Cases. Rational Software White Paper.
- Sindre, G. and Opdahl, A. (2001) Capturing Security Requirements through Misuse Cases. Proceedings of the 14th Norsk Information Conference (NIK2001), Tromso, 26-28 November 2001, 212-221.
- Srivatanakul, T., Clark, J. and Polack, F. (2004) Writing Effective Security Abuse Cases. Technical Report YCS-2004-375. University of York, York.