Design of Secure and Traceable Requirement Engineering Process for Security-Sensitive Projects
- 1 Department of Computer Science, Virtual University, Lahore, Pakistan
- 2 Department of Computer Science, Preston University, Islamabad, Pakistan
- 3 Department of Computer Science, Virtual University, Lahore, Pakistan
- 4 Department of Computer Science, Beijing University of Technology, Beijing, China
Abstract
With continuous evolution in software industry, security is becoming very important in software projects. However, in many development methodologies, security is thought to be added in the project at later stages of the development lifecycle. There are also many proposed methodologies where the security measures are considered at requirement engineering stage of the development lifecycle, but many of them still do not seem adequate for applicability due to the reason that these approaches do not provide sufficient support for mapping the security requirements to the later stages of development. So, we are in need of a software requirement engineering approach, which is not only helpful in security requirement specification at requirement engineering stage but also provides support for using the specified security requirements at later stages of development. To meet this requirement, we introduce a new method Secure and Traceable Requirement Engineering Process (STREP). This method also helps the non-security-expert requirement engineers to specify requirements in such a way that the specified requirements can be used to derive security related test cases. STREP method not only deals with security issues of the system at requirement engineering stage, but also makes the security requirements more traceable to be used at later stages of development lifecycle, and as a result, secure systems are produced that are also usable as the customer wishes.
- Hoegh, R.T. (2006) Usability Problems: Do Software Developers Already Know? Aalborg University Department of Computer Science, Aalborg East, DK-9220, Denmark.
- De Landtsheer, R. and van Lamsweerde, A. (2005) Reasoning About Confidentiality at Requirements Engineering Time. Département d’Ingénierie Informatique, Université catholique de Louvain B-1348 Louvain-la-Neuve (Belgium).
- Romero Mariona, J. and Richardson, D. (2009) Security Requirements Engineering: A Survey. University of California, Irvine.
- Whittle, J. and Wijesekera, D. (2008) Executable Misuse Cases for Modeling Security Concerns. Federal Railroad Administration 1120 Vermont Ave Washington, DC 20590.
- Viega, J. (2005) Building Security Requirements with CLASP. Secure Software, Inc. 2010 Corporate Ridge, Suite 820 McClean, VA.
- Futcher, L. and von Solms, R. (2008) Guidelines for Secure Software Development. Nelson Mandela Metropolitan University P O Box 77000, Port Elizabeth, 6031 South Africa.
- Software Quality Attributes and Trade-Offs. (2005) Authors: Patrik Berander, Lars-Ola Damm, Jeanette Eriksson, Tony Gorschek, Kennet Henningsson, Per Jönsson, Simon Kågström, Drazen Milicic, Frans Mårtensson, Kari Rönkkö, Piotr Tomaszewski.
- Constantine, L.L. and Lockwood, L.A.D. (2003) Usage-Centred Software Engineering: An Agile Approach to Integrating Users, User Interfaces, and Usability into Software Engineering Practice. University of technology, Sydney (Australia), Constantine & Lockwood, Ltd.
- Beznosov, K. and Kruchten, P. (2004) Towards Agile Security Assurance. University of British Columbia 2356 Main Mall Vancouver, BC, V6T 4Z1 Canada.
- Luckey, M., Baumann, A. and Méndez, D. (2010) Reusing Security Requirements Using an Extended Quality Model. University of Paderborn, Paderborn.
- Mead, N.R. and Stehney, T. (2005) Security Quality Requirements Engineering (SQUARE) Methodology. Carnegie Mellon University 5000 Forbes Avenue Pittsburgh.
- Ardi, S., Byers, D. and Shahmehri, N. (2006) Towards a Structured Unified Process for Software Security. Department of Computer and Information Science Linköping University, SE-58183 Linköping, Sweden.
- Romero-Mariona, J. and Ziv, H. (2009) Later Stages Support for Security Requirements. University of California, Irvine Donald Bren School of Information and Computer Sciences.