Universiti Teknologi Malaysia Institutional Repository

The state of the art on secure software engineering: A systematic mapping study

Khan, Rafiq A. and Khan, Siffat U. and Muhammad Ilyas, Muhammad Ilyas and Idris, Mohd. Y. (2020) The state of the art on secure software engineering: A systematic mapping study. In: 24th Evaluation and Assessment in Software Engineering Conference, EASE 2020, 15 - 17 April 2020, Trondheim, Online.

Full text not available from this repository.

Official URL: http://dx.doi.org/10.1145/3383219.3383290

Abstract

Secure Software Development (SSD) is becoming a major challenge, due to the increasing complexity, openness and extensibility of Information and Communication Technologies (ICTs). These make the overall security requirements analysis very difficult. Many techniques have been theoretically developed, however, there is a lack of empirical evidence of its application in building secure software system. A Systematic Mapping Study (SMS) has been conducted in this paper to examine the existence of software security frameworks, models and methods. In total, we selected 116 primary studies. After examining the selected studies, we identified 37 Secure Software Engineering (SSE) paradigms/frameworks/models. The results show that the most frequently used SSE frameworks/models are "Microsoft Software Development Life Cycle (MS-SDL)", "Misuse case modeling", "Abuse case modeling", "Knowledge Acquisition for Automated Specification", "System Security Engineering-Capability Maturity Model (SSE-CMM)"and "Secure Tropos Methodology". This work will help organizations in the development of software to better understand existing security initiatives used in the development of secure software. It can also provide researchers with a basis for designing and developing new methods of software security and identifying new axis of research.

Item Type:Conference or Workshop Item (Paper)
Uncontrolled Keywords:Software Development Life Cycle, Systematic mapping study
Subjects:Q Science > QA Mathematics > QA75 Electronic computers. Computer science
Divisions:Computing
ID Code:92570
Deposited By: Widya Wahid
Deposited On:30 Sep 2021 15:14
Last Modified:30 Sep 2021 15:14

Repository Staff Only: item control page