DocumentCode :
652642
Title :
An Experimental Comparison of Two Risk-Based Security Methods
Author :
Labunets, Katsiaryna ; Massacci, F. ; Paci, Federica ; Le Minh Sang Tran
Author_Institution :
DISI, Univ. of Trento Trento, Trento, Italy
fYear :
2013
fDate :
10-11 Oct. 2013
Firstpage :
163
Lastpage :
172
Abstract :
A significant number of methods have been proposed to identify and analyze threats and security requirements, but there are few empirical evaluations that show these methods work in practice. This paper reports a controlled experiment conducted with 28 master students to compare two classes of risk-based methods, visual methods (CORAS) and textual methods (SREP). The aim of the experiment was to compare the effectiveness and perception of the two methods. The participants divided in groups solved four different tasks by applying the two methods using a randomized block design. The dependent variables were effectiveness of the methods measured as number of threats and security requirements identified, and perception of the methods measured through a post-task questionnaire based on the Technology Acceptance Model. The experiment was complemented with participants´ interviews to determine which features of the methods influence their effectiveness. The main findings were that the visual method is more effective for identifying threats than the textual one, while the textual method is slightly more effective for eliciting security requirements. In addition, visual method overall perception and intention to use were higher than for the textual method.
Keywords :
risk analysis; security of data; CORAS; SREP; experimental comparison; randomized block design; risk-based security methods; security requirements; technology acceptance model; textual methods; threat analysis; threat identification; visual methods; Atmospheric measurements; Interviews; Particle measurements; Risk analysis; Security; Smart grids; Visualization; controlled experiment; risk-based methods; technology acceptance model;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Empirical Software Engineering and Measurement, 2013 ACM / IEEE International Symposium on
Conference_Location :
Baltimore, MD
ISSN :
1938-6451
Print_ISBN :
978-0-7695-5056-5
Type :
conf
DOI :
10.1109/ESEM.2013.29
Filename :
6681349
Link To Document :
بازگشت