Prioritizing Industrial Security Findings in Agile Software Development Projects

被引:1
|
作者
Voggenreiter, Markus [1 ]
Schoepp, Ulrich [2 ]
机构
[1] Ludwig Maximilians Univ Munchen, Siemens Technol, Munich, Germany
[2] Fortiss GmbH, Munich, Germany
来源
2023 IEEE/ACM 45TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING: COMPANION PROCEEDINGS, ICSE-COMPANION | 2023年
关键词
agile; security findings; software engineering; prioritization;
D O I
10.1109/ICSE-Companion58688.2023.00106
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Automating repetitive activities is a key principle in most software development approaches employed in the industry. This implies that security activities and all related processes should be investigated for automation capabilities, particularly the management of security findings and vulnerabilities. Considering the limited time available for each release and the vast flood of findings by automated security testing, prioritizing security finding responses is essential. In this paper, we present a partially automated process to prioritize security findings in industrial software development projects. We utilize a two-staged calculation process to produce a prioritization score, representing the finding's severity and factors like stakeholder input alike. This process was evaluated by conducting structured interviews with security professionals while also integrating the approach in ongoing industrial software development projects. The results indicate the potential of the process in terms of usefulness and correctness for agile software development projects.
引用
收藏
页码:375 / 379
页数:5
相关论文
共 50 条
  • [41] Collaboration and Human Factors in Software Development Teaching Agile Methodologies based on Industrial Insight
    Kropp, Martin
    Meier, Andreas
    PROCEEDINGS OF 2016 IEEE GLOBAL ENGINEERING EDUCATION CONFERENCE (EDUCON2016), 2016, : 1003 - 1011
  • [42] Discovering undocumented knowledge through visualization of agile software development activitiesCase studies on industrial projects using issue tracking system and version control system
    Shinobu Saito
    Yukako Iimura
    Aaron K. Massey
    Annie I. Antón
    Requirements Engineering, 2018, 23 : 381 - 399
  • [43] Data Mining Approach to Effort Modeling on Agile Software Projects
    Karna, Hrvoje
    Gotovac, Sven
    Vickovic, Linda
    INFORMATICA-AN INTERNATIONAL JOURNAL OF COMPUTING AND INFORMATICS, 2020, 44 (02): : 231 - 239
  • [44] Designing and applying an approach to software architecting in agile projects in education
    Angelov, S.
    de Beer, P.
    JOURNAL OF SYSTEMS AND SOFTWARE, 2017, 127 : 78 - 90
  • [45] Estimation of agile functionality in software development
    Nasr-Azadani, Bashir
    MohammadDoost, Reza
    IMECS 2008: INTERNATIONAL MULTICONFERENCE OF ENGINEERS AND COMPUTER SCIENTISTS, VOLS I AND II, 2008, : 955 - 957
  • [46] A decade of agile methodologies: Towards explaining agile software development
    Dingsoyr, Torgeir
    Nerur, Sridhar
    Balijepally, VenuGopal
    Moe, Nils Brede
    JOURNAL OF SYSTEMS AND SOFTWARE, 2012, 85 (06) : 1213 - 1221
  • [47] Coaching the application of agile software development
    Wendorff, Peter
    Organizational Dynamics of Technology-Based Innovation: Diversifying the Research Agenda, 2007, 235 : 519 - 523
  • [48] Distributed agile software development for the SKA
    Wicenec, Andreas
    Parsons, Rebecca
    Kitaeff, Slava
    Vinsen, Kevin
    Wu, Chen
    Nelson, Paul
    Reed, David
    SOFTWARE AND CYBERINFRASTRUCTURE FOR ASTRONOMY II, 2012, 8451
  • [49] Creativity in Agile Software Development Methods
    Crawford, Broderick
    Crawford, Kathleen
    Soto, Ricardo
    Leon de la Barra, Claudio
    HCI INTERNATIONAL 2015 - POSTERS' EXTENDED ABSTRACTS, PT II, 2015, 529 : 131 - 135
  • [50] Development of Complex Software with Agile Method
    Braz, Alan
    Rubira, Cecilia M. F.
    Vieira, Marco
    2015 AGILE CONFERENCE, 2015, : 97 - 101