Title :
Using malware analysis to improve security requirements on future systems
Author :
Mead, Nancy R. ; Morales, Jose Andre
Author_Institution :
Software Eng. Inst., Carnegie Mellon Univ., Pittsburgh, PA, USA
Abstract :
In this position paper, we propose to enhance current software development lifecycle models by including use cases, based on previous cyberattacks and their associated malware, and to propose an open research question: Are specific types of systems prone to specific classes of malware exploits? If this is the case, developers can create future systems that are more secure, from inception, by including use cases that address previous attacks.
Keywords :
invasive software; software engineering; cyberattacks; malware analysis; malware exploits; security requirement improvement; software development lifecycle models; use cases; Authentication; Computer crime; Malware; Software; Software engineering; Standards; SDLC; cyberattacks; malware; software security;
Conference_Titel :
Evolving Security and Privacy Requirements Engineering (ESPRE), 2014 IEEE 1st Workshop on
Conference_Location :
Karlskrona
DOI :
10.1109/ESPRE.2014.6890526