Using abuse frames to bound the scope of security problems
Luncheng Lin, Bashar Nuseibeh, D. C. Ince, Michael Jackson
Abstract
Open-access reader
Luncheng Lin, Bashar Nuseibeh, D. C. Ince, Michael Jackson
Abstract
Open-access reader
Security problems arise from the concern for \nprotecting assets from security threats. In a systems \ndevelopment process, the security protection of a system \nis specified by security requirements, identified from the \nanalysis of the threats to the system. However, as it is \noften not possible to obtain a full system description until \nlate in the RE process, a security problem often has to be \ndescribed in the context of a bounded scope, that is, one \ncontaining only the domains relevant to some part of the \nfunctionality of the full system. By binding the scope of a \nsecurity problem, it can be described more explicitly and \nprecisely, thereby facilitating the identification and \nanalysis of threats, which in turn drive the elicitation and \nelaboration of security requirements. In this poster, we \nelaborate on an approach we developed based on abuse \nframes and suggest how it can provide a means for \nstructuring and bounding the scope security problems.
OpenAlex reports 63 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Security problems arise from the concern for \nprotecting assets from security threats. In a systems \ndevelopment process, the security protection of a system \nis specified by security requirements, identified from the \nanalysis of the threats to the system. However, as it is \noften not possible to obtain a full system description until \nlate in the RE process, a security problem often has to be \ndescribed in the context of a bounded scope, that is, one \ncontaining only the domains relevant to some part of the \nfunctionality of the full system. By binding the scope of a \nsecurity problem, it can be described more explicitly and \nprecisely, thereby facilitating the identification and \nanalysis of threats, which in turn drive the elicitation and \nelaboration of security requirements. In this poster, we \nelaborate on an approach we developed based on abuse \nframes and suggest how it can provide a means for \nstructuring and bounding the scope security problems.
Key concepts: Scope (computer science), Computer science, Computer security, Structuring, Bounding overwatch, Computer security model, Security through obscurity, Context (archaeology)