• DocumentCode
    3668181
  • Title

    Functional requirements under security PresSuRE

  • Author

    Stephan Faßbender;Maritta Heisel;Rene Meis

  • Author_Institution
    paluno - The Ruhr Institute for Software Technology, University of Duisburg-Essen, Germany
  • fYear
    2014
  • Firstpage
    5
  • Lastpage
    16
  • Abstract
    Recently, there has been an increase of reported security incidents hitting large software systems. Such incidents can originate from different attackers exploiting vulnerabilities of different parts of a system. Hence, there is a need for enhancing security considerations in software development. It is crucial for requirements engineers to identify security threats early on, and to refine the threats into security requirements. In this paper, we introduce a methodology for Problem-based Security Requirements Elicitation (PresSuRE). PresSuRE is a method for identifying security needs during the requirements analysis of software systems using a problem frame model. Our method does not rely entirely on the requirements engineer to detect security needs, but provides a computer-aided security threat identification, and subsequently the elicitation of security requirements. The identification is based on the functional requirements for a system-to-be. We illustrate and validate our approach using a smart grid scenario provided by the industrial partners of the EU project NESSoS.
  • Keywords
    "Security","Smart meters","Unified modeling language","Logic gates","Stakeholders","Smart grids","Wide area networks"
  • Publisher
    ieee
  • Conference_Titel
    Software Paradigm Trends (ICSOFT-PT), 2014 9th International Conference on
  • Type

    conf

  • Filename
    7292568