System security requirements: A framework for early identification, specification and measurement of related software requirements

被引:11
|
作者
Meridji, Kenza [1 ]
Al-Sarayreh, Khalid T. [2 ]
Abran, Alain [3 ]
Trudel, Sylvie [4 ]
机构
[1] Univ Petra, Coll Informat Technol, Software Engn Dept, Queen Alia St,POB 961343, Amman 11196, Jordan
[2] Hashemite Univ, Prince Hussein Bin Abdullah II Informat Technol, Software Engn Dept, POB 330127, Zarqa 13133, Jordan
[3] Univ Quebec, ETS, Software Engn & Informat Technol Dept, 1100 Notre Dame St West, Montreal, PQ H3C 1K3, Canada
[4] Univ Quebec, Dept Informat, CP 8888,Succ Ctr Ville, Montreal, PQ H3C 3P8, Canada
关键词
Non-functional requirements (NFR); Security requirements; International standards; Security measurement; Soft-goal interdependency; Graphs (SIG); COSMIC; -; ISO; 19761; COSMIC-SOA; NONFUNCTIONAL REQUIREMENTS; MODEL;
D O I
10.1016/j.csi.2019.04.005
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
One of the responsibilities of developers is the early definition of non-functional requirements (NFR) at the system level and their related allocation as functional user requirements (FUR) at the software level. To identify some of the widely consensual security elements that could be used in a standards-based security framework, the security-related terminology and views from three sets of international standards (ECSS, IEEE and ISO) are analyzed and integrated. Next, the set of concepts adopted by ISO 19761 for describing software functionality at a lower level are introduced, thereby ensuring that the proposed framework is designed for measurement purposes as well. For the capture of security concepts, the proposed framework is designed using soft-goal interdependency graphs (SIG) and three main system NFR-security types: system availability, confidentiality and integrity. This standards-based system security framework at the function and service level can support software developers to derive such requirements in the early stages of the development process. Finally, an ATM example for the measurement of system security NFR allocated as software FUR within a service-oriented architecture (SOA) is presented.
引用
收藏
页数:20
相关论文
共 50 条
  • [1] A framework for evaluating system and software requirements specification approaches
    Kamsties, E
    Rombach, HD
    REQUIREMENTS TARGETING SOFTWARE AND SYSTEMS ENGINEERING, 1998, 1526 : 203 - 222
  • [2] Framework for Fast Building Software Requirements Specification
    Singchai, Ponglikit
    Rivepiboon, Wanchai
    2013 INTERNATIONAL CONFERENCE ON INDUSTRIAL ENGINEERING AND MANAGEMENT SCIENCE (ICIEMS 2013), 2013, : 1337 - 1343
  • [3] Software requirements specification and system safety
    Heimdahl, MPE
    Reese, JD
    RE '97 - PROCEEDINGS OF THE THIRD IEEE INTERNATIONAL SYMPOSIUM ON REQUIREMENTS ENGINEERING, 1997, : 264 - 264
  • [4] A Security Focus to the IEEE CONOPS and Software Requirements Specification
    Riley, Jack Wesley
    Dampier, David A.
    Vaughn, Rayford B.
    WMSCI 2008: 12TH WORLD MULTI-CONFERENCE ON SYSTEMICS, CYBERNETICS AND INFORMATICS, VOL V, PROCEEDINGS, 2008, : 143 - 146
  • [5] Annotation of Software Requirements Specification (SRS), Extractions of Nonfunctional Requirements, and Measurement of Their Tradeoff
    Asif, Muhammad
    Ali, Ishfaq
    Malik, Muhamad Sheraz Arshed
    Chaudary, Muhammad Hasanain
    Tayyaba, Shahzadi
    Mahmood, Muhammad Tariq
    IEEE ACCESS, 2019, 7 : 36164 - 36176
  • [6] Ontology based Framework for DetectingAmbiguities in Software Requirements Specification
    Bhatia, M. P. S.
    Kumar, Akshi
    Beniwal, Rohit
    PROCEEDINGS OF THE 10TH INDIACOM - 2016 3RD INTERNATIONAL CONFERENCE ON COMPUTING FOR SUSTAINABLE GLOBAL DEVELOPMENT, 2016, : 3572 - 3575
  • [7] A Tool-based Semantic Framework for Security Requirements Specification
    Daramola, Olawande
    Sindre, Guttorm
    Moser, Thomas
    JOURNAL OF UNIVERSAL COMPUTER SCIENCE, 2013, 19 (13) : 1940 - 1962
  • [8] Early Software Quality Prediction Based on Software Requirements Specification Using Fuzzy Inference System
    Masood, Muhammad Hammad
    Khan, Malik Jahan
    INTELLIGENT COMPUTING METHODOLOGIES, ICIC 2018, PT III, 2018, 10956 : 722 - 733
  • [9] Security requirements engineering framework for software product lines
    Mellado, Daniel
    Fernandez-Medina, Eduardo
    Piattini, Mario
    INFORMATION AND SOFTWARE TECHNOLOGY, 2010, 52 (10) : 1094 - 1117
  • [10] Measurement Model of Software Requirements Derived from System Maintainability Requirements
    Abran, Alain
    Al-Sarayreh, Khalid T.
    Cuadrado-Gallego, Juan J.
    22ND INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING & KNOWLEDGE ENGINEERING (SEKE 2010), 2010, : 153 - 158