DocumentCode
759078
Title
A Metrics Framework to Drive Application Security Improvement
Author
Nichols, Elizabeth A. ; Peterson, Gunnar
Volume
5
Issue
2
fYear
2007
Firstpage
88
Lastpage
91
Abstract
Web applications\´ functionality and user base have evolved along with the threat landscape. Although controls such as network firewalls are essential, they\´re wholly insufficient for providing overall Web application security. They provide security for underlying hosts and a means of communication, but do little to aid the application resist attack against its software implementation or design. Enterprises must therefore focus on the security of the Web application itself. But in doing so, questions immediately arise: "What could go wrong with my software? How vulnerable are my existing applications to the most common problems? What changes to my software development life cycle might affect these vulnerabilities?" The Open Web Application Security Project (OWASP; www.owa sp.org) Top Ten offers a starting point for figuring out what could go wrong. This installment of Building Security In presents metrics that can help quantify the impact that process changes in one life-cycle phase have on other phases. For the purposes of this short discussion, we\´ve broken an applications life cycle into three main phases: design, deployment, and runtime. By organizing metrics according to life cycle in addition to OWASP type, insight from the derived quantitative results can potentially point to defective processes and even suggest strategies for improvement
Keywords
security of data; software metrics; Open Web Application Security Project; Web application functionality; Web application security; application life cycle; application security improvement; metrics framework; network firewall; process changes; Application software; Authentication; Buffer overflow; Buildings; Computer interfaces; Computer security; Drives; HTML; Privacy; Runtime; life cycle; metrics; software development; software engineering; software management;
fLanguage
English
Journal_Title
Security & Privacy, IEEE
Publisher
ieee
ISSN
1540-7993
Type
jour
DOI
10.1109/MSP.2007.26
Filename
4140998
Link To Document