مرکز اطلاعات علمی Scientific Information Database (SID) - Trusted Source for Research and Academic Resources

Persian Verion

مرکز اطلاعات علمی Scientific Information Database (SID) - Trusted Source for Research and Academic Resources

video

مرکز اطلاعات علمی Scientific Information Database (SID) - Trusted Source for Research and Academic Resources

sound

مرکز اطلاعات علمی Scientific Information Database (SID) - Trusted Source for Research and Academic Resources

Persian Version

مرکز اطلاعات علمی Scientific Information Database (SID) - Trusted Source for Research and Academic Resources

View:

495
مرکز اطلاعات علمی Scientific Information Database (SID) - Trusted Source for Research and Academic Resources

Download:

243
مرکز اطلاعات علمی Scientific Information Database (SID) - Trusted Source for Research and Academic Resources

Cites:

Information Journal Paper

Title

QUANTITATIVE EVALUATION OF SOFTWARE SECURITY: AN APPROACH BASED ON UML/SECAM AND EVIDENCE THEORY

Pages

  143-155

Abstract

 Quantitative and model-based prediction of security in the architecture design stage facilitates early detection of design faults hence reducing modification costs in subsequent stages of software life cycle. However, an important question arises with respect to the accuracy of input parameters. In practice, security parameters can rarely be estimated accurately due to the lack of sufficient knowledge. This inaccuracy is ignored in most of the existing evaluation methods. The aim of this paper is to explicitly consider parameter uncertainty in the software SECURITY EVALUATION process. In particular, we use the Dempster-Shafer theory of evidence to formulate the uncertainties in input parameters and determine their effects on output measures. In the proposed method, security attacks are expressed using UML diagrams (i.e., misuse case and mal-activity diagrams) and security parameters are specified using the SecAM profile. UML/SecAM models are then transformed into attack trees, which allow quantifying the probability of security breaches. The applicability of the method is validated by a case study on an online marketing system.

Cites

  • No record.
  • References

  • No record.
  • Cite

    APA: Copy

    SEDAGHATBAF, ALI, & ABDOLLAHI AZGOMI, MOHAMMAD. (2016). QUANTITATIVE EVALUATION OF SOFTWARE SECURITY: AN APPROACH BASED ON UML/SECAM AND EVIDENCE THEORY. THE ISC INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 8(2 ), 143-155. SID. https://sid.ir/paper/241776/en

    Vancouver: Copy

    SEDAGHATBAF ALI, ABDOLLAHI AZGOMI MOHAMMAD. QUANTITATIVE EVALUATION OF SOFTWARE SECURITY: AN APPROACH BASED ON UML/SECAM AND EVIDENCE THEORY. THE ISC INTERNATIONAL JOURNAL OF INFORMATION SECURITY[Internet]. 2016;8(2 ):143-155. Available from: https://sid.ir/paper/241776/en

    IEEE: Copy

    ALI SEDAGHATBAF, and MOHAMMAD ABDOLLAHI AZGOMI, “QUANTITATIVE EVALUATION OF SOFTWARE SECURITY: AN APPROACH BASED ON UML/SECAM AND EVIDENCE THEORY,” THE ISC INTERNATIONAL JOURNAL OF INFORMATION SECURITY, vol. 8, no. 2 , pp. 143–155, 2016, [Online]. Available: https://sid.ir/paper/241776/en

    Related Journal Papers

    Related Seminar Papers

  • No record.
  • Related Plans

  • No record.
  • Recommended Workshops






    Move to top
    telegram sharing button
    whatsapp sharing button
    linkedin sharing button
    twitter sharing button
    email sharing button
    email sharing button
    email sharing button
    sharethis sharing button