首页    期刊浏览 2025年02月22日 星期六
登录注册

文章基本信息

  • 标题:A Method for Developing Abuse Cases and Its Evaluation
  • 本地全文:下载
  • 作者:Imano Williams ; Xiaohong Yuan ; Jeffrey Todd McDonald
  • 期刊名称:Journal of Software
  • 印刷版ISSN:1796-217X
  • 出版年度:2016
  • 卷号:11
  • 期号:5
  • 页码:520-527
  • DOI:10.17706/jsw.11.5.520-527
  • 出版社:Academy Publisher
  • 摘要:To develop secure software, software engineers need to have the mindset of attackers. Developing abuse cases can help software engineers to think more like attackers. This paper describes a method for developing abuse cases based on threat modeling, attack patterns, and Common Weakness Enumeration. The method also includes ranking the abuse cases according to their risks. This method intends to help non-experts create abuse cases following a specific process, and leveraging the knowledge bases of threat modeling, attack patterns, and Common Weakness Enumeration. The proposed method was evaluated through two evaluation studies conducted in two secure software engineering courses at two different universities. Evaluation studies show that the proposed method was easier to follow by non-experts in generating abuse cases than brainstorming, and could reduce the time needed for creating abuse cases. Other findings from the evaluation studies are also discussed in the paper.
  • 其他关键词:Abuse cases, threat modeling, attack patterns, common weakness enumeration, secure software development.
国家哲学社会科学文献中心版权所有