Composing Security Metrics

Author(s):  
Matt Blaze
Keyword(s):  
2011 ◽  
Vol E94-B (6) ◽  
pp. 1625-1629
Author(s):  
Atsufumi MORIYAMA ◽  
Hiroshi ISHINISHI ◽  
Katsuichi NAKAMURA ◽  
Yoshiaki HORI

Author(s):  
Sampada G.C ◽  
Tende Ivo Sake ◽  
Amrita

Background: With the advancement in the field of software development, software poses threats and risks to customers’ data and privacy. Most of these threats are persistent because security is mostly considered as a feature or a non-functional requirement, not taken into account during the software development life cycle (SDLC). Introduction: In order to evaluate the security performance of a software system, it is necessary to integrate the security metrics during the SDLC. The appropriate security metrics adopted for each phase of SDLC aids in defining the security goals and objectives of the software as well as quantify the security in the software. Methods: This paper presents systematic review and catalog of security metrics that can be adopted during the distinguishable phases of SDLC, security metrics for vulnerability and risk assessment reported in the literature for secure development of software. The practices of these metrics enable software security experts to improve the security characteristics of the software being developed. The critical analysis of security metrics of each phase and their comparison are also discussed. Results: Security metrics obtained during the development processes help to improve the confidentiality, integrity, and availability of software. Hence, it is imperative to consider security during the development of the software, which can be done with the use of software security metrics. Conclusion: This paper reviews the various security metrics that are meditated in the copious phases during the progression of the SDLC in order to provide researchers and practitioners with substantial knowledge for adaptation and further security assessment.


Author(s):  
Sauvagya Ranjan Sahoo ◽  
Sudeendra Kumar ◽  
Kamalakanta Mahapatra
Keyword(s):  

Author(s):  
George O.M. Yee

This article begins with an introduction to security metrics, describing the need for security metrics, followed by a discussion of the nature of security metrics, including the challenges found with some security metrics used in the past. The article then discusses what makes a sound security metric and proposes a rigorous step-by-step method that can be applied to design sound security metrics, and to test existing security metrics to see if they are sound metrics. This is followed by a discussion of the feasibility of having scientifically-based security metrics and whether or not such metrics are sound. Application examples are included to illustrate the design and testing of sound security metrics.


Sign in / Sign up

Export Citation Format

Share Document