2004Open Research Online (The Open University)Requires access

Using abuse frames to bound the scope of security problems

Luncheng Lin, Bashar Nuseibeh, D. C. Ince, Michael Jackson

Open publisher page 63 citations

Abstract

Security problems arise from the concern for \nprotecting assets from security threats. In a systems \ndevelopment process, the security protection of a system \nis specified by security requirements, identified from the \nanalysis of the threats to the system. However, as it is \noften not possible to obtain a full system description until \nlate in the RE process, a security problem often has to be \ndescribed in the context of a bounded scope, that is, one \ncontaining only the domains relevant to some part of the \nfunctionality of the full system. By binding the scope of a \nsecurity problem, it can be described more explicitly and \nprecisely, thereby facilitating the identification and \nanalysis of threats, which in turn drive the elicitation and \nelaboration of security requirements. In this poster, we \nelaborate on an approach we developed based on abuse \nframes and suggest how it can provide a means for \nstructuring and bounding the scope security problems.

Open-access reader

About this research paper

What this paper is about

Security problems arise from the concern for \nprotecting assets from security threats. In a systems \ndevelopment process, the security protection of a system \nis specified by security requirements, identified from the \nanalysis of the threats to the system. However, as it is \noften not possible to obtain a full system description until \nlate in the RE process, a security problem often has to be \ndescribed in the context of a bounded scope, that is, one \ncontaining only the domains relevant to some part of the \nfunctionality of the full system. By binding the scope of a \nsecurity problem, it can be described more explicitly and \nprecisely, thereby facilitating the identification and \nanalysis of threats, which in turn drive the elicitation and \nelaboration of security requirements. In this poster, we \nelaborate on an approach we developed based on abuse \nframes and suggest how it can provide a means for \nstructuring and bounding the scope security problems.

Why it matters

OpenAlex reports 63 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Security problems arise from the concern for \nprotecting assets from security threats. In a systems \ndevelopment process, the security protection of a system \nis specified by security requirements, identified from the \nanalysis of the threats to the system. However, as it is \noften not possible to obtain a full system description until \nlate in the RE process, a security problem often has to be \ndescribed in the context of a bounded scope, that is, one \ncontaining only the domains relevant to some part of the \nfunctionality of the full system. By binding the scope of a \nsecurity problem, it can be described more explicitly and \nprecisely, thereby facilitating the identification and \nanalysis of threats, which in turn drive the elicitation and \nelaboration of security requirements. In this poster, we \nelaborate on an approach we developed based on abuse \nframes and suggest how it can provide a means for \nstructuring and bounding the scope security problems.

Key concepts: Scope (computer science), Computer science, Computer security, Structuring, Bounding overwatch, Computer security model, Security through obscurity, Context (archaeology)

Related papers

Back to paper searchBrowse research topicsOriginal source
Using abuse frames to bound the scope of security problems — Research Paper | ScholarLens