• DocumentCode
    1833129
  • Title

    Experimental Comparison of Misuse Case Maps with Misuse Cases and System Architecture Diagrams for Eliciting Security Vulnerabilities and Mitigations

  • Author

    Karpati, Peter ; Opdahl, Andreas L. ; Sindre, Guttorm

  • Author_Institution
    Dept. of Comput. & Inf. Sci., Norwegian Univ. of Sci. & Technol., Trondheim, Norway
  • fYear
    2011
  • fDate
    22-26 Aug. 2011
  • Firstpage
    507
  • Lastpage
    514
  • Abstract
    The idea of security aware system development from the start of the engineering process is generally accepted nowadays and is becoming applied in practice. Many recent initiatives support this idea with special focus on security requirements elicitation. However, there are so far no techniques that provide integrated overviews of security threats and system architecture. One way to achieve this is by combining misuse cases with use case maps into misuse case maps (MUCM). This paper presents an experimental evaluation of MUCM diagrams focusing on identification of vulnerabilities and mitigations. The controlled experiment with 33 IT students included a complex hacker intrusion from the literature, illustrated either with MUCM or with alternative diagrams. The results suggest that participants using MUCM found significantly more mitigations than participants using regular misuse cases combined with system architecture diagrams.
  • Keywords
    formal specification; security of data; software architecture; systems analysis; complex hacker intrusion; misuse case map; security aware system development; security requirement elicitation; security threat; security vulnerability elicitation; security vulnerability mitigation; system architecture diagram; vulnerability identification; Computer architecture; Computer hacking; Computers; Encoding; Software; Unified modeling language; architectural view; controlled experiment; intrusion analysis; misuse case maps; misuse cases; security requirements;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Availability, Reliability and Security (ARES), 2011 Sixth International Conference on
  • Conference_Location
    Vienna
  • Print_ISBN
    978-1-4577-0979-1
  • Electronic_ISBN
    978-0-7695-4485-4
  • Type

    conf

  • DOI
    10.1109/ARES.2011.77
  • Filename
    6046008