• DocumentCode
    2411182
  • Title

    Increasing Trustworthiness through Security Testing Support

  • Author

    Romero-Mariona, Jose ; Ziv, Hadar ; Richardson, Debra

  • Author_Institution
    Irvine Donald Bren Sch. of Inf. & Comput. Sci., Univ. of California, Irvine, CA, USA
  • fYear
    2010
  • fDate
    20-22 Aug. 2010
  • Firstpage
    920
  • Lastpage
    925
  • Abstract
    Trustworthiness is an essential and sometimes life-critical concern in software-intensive systems. Furthermore, supporting the proper testing of these systems can often times prove complicated. Within trustworthiness, security and privacy play key roles. Considering both security and privacy issues early in development are necessary to increase the trustworthiness of systems. In this paper we concentrate on the security aspect of trustworthiness. We believe that proper capture of software security starts at requirements and carries forward throughout system development, especially into testing. While a variety of techniques for specifying security requirements exist, there is a tangible lack of support for making security requirements useful during testing. In this paper we present testing capabilities of a new security requirements engineering technique called SURE, Secure and Usable Requirements Engineering. SURE focuses on the mapping of security requirements into testing artifacts using a specialized syntax. We also present results from a usability study of our technique´s testing capabilities; the study confirmed that participants were able to map testing artifacts from security requirements with increased understanding and confidence, which could potentially lead to improved trustworthiness.
  • Keywords
    program testing; security of data; SURE; secure and usable requirements engineering; security requirements engineering; security testing support; software security; software-intensive systems; trustworthiness; Biological system modeling; Industries; Privacy; Security; Software; Syntactics; Testing; security requirements; security requirements-based testing; usable requirements;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Social Computing (SocialCom), 2010 IEEE Second International Conference on
  • Conference_Location
    Minneapolis, MN
  • Print_ISBN
    978-1-4244-8439-3
  • Electronic_ISBN
    978-0-7695-4211-9
  • Type

    conf

  • DOI
    10.1109/SocialCom.2010.136
  • Filename
    5591421