Endre søk
RefereraExporteraLink to record
Permanent link

Direct link
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annet format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annet språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf
An efficient approach for reviewing security-related aspects in agile requirements specifications of web applications
Pontifical Catholic University of Rio de Janeiro, BRA.
Pontifical Catholic University of Rio de Janeiro, BRA.
Pontifical Catholic University of Rio de Janeiro, BRA.
Blekinge Tekniska Högskola, Fakulteten för datavetenskaper, Institutionen för programvaruteknik.
2020 (engelsk)Inngår i: Requirements Engineering, ISSN 0947-3602, E-ISSN 1432-010X, Vol. 25, nr 4, s. 439-468, artikkel-id Special Issue: SIArtikkel i tidsskrift (Fagfellevurdert) Published
Abstract [en]

Defects in requirement specifications can have severe consequences during the software development life cycle. Some of them may result in poor product quality and/or time and budget overrun due to incorrect or missing quality characteristics, such as security. This characteristic requires special attention in web applications because they have become a target for manipulating sensible data. Several concerns make security difficult to deal with. For instance, security requirements are often misunderstood and improperly specified due to lack of security expertise and emphasis on security during early stages of software development. This often leads to unspecified or ill-defined security-related aspects. These concerns become even more challenging in agile contexts, where lightweight documentation is typically produced. To tackle this problem, we designed an approach for reviewing security-related aspects in agile requirements specifications of web applications. Our proposal considers user stories and security specifications as inputs and relates those user stories to security properties via natural language processing. Based on the related security properties, our approach identifies high-level security requirements from the Open Web Application Security Project (OWASP) to be verified and generates a reading technique to support reviewers in detecting defects. We evaluate our approach via three experimental trials conducted with 56 novice software engineers, measuring effectiveness, efficiency, usefulness and ease of use. We compare our approach against using: (1) the OWASP high-level security requirements and (2) a perspective-based approach as proposed in contemporary state of the art. The results strengthen our confidence that using our approach has a positive impact (with large effect size) on the performance of inspectors in terms of effectiveness and efficiency. © 2020, Springer-Verlag London Ltd., part of Springer Nature.

sted, utgiver, år, opplag, sider
Springer Science and Business Media Deutschland GmbH , 2020. Vol. 25, nr 4, s. 439-468, artikkel-id Special Issue: SI
Emneord [en]
Agile requirements, Requirement verification, Software inspection, Software security, Budget control, Computer software, Cryptography, Defects, Efficiency, Life cycle, Natural language processing systems, Software design, Specifications, Effectiveness and efficiencies, Experimental trials, NAtural language processing, Open web application security projects, Quality characteristic, Requirement specification, Security requirements, Software development life cycle, Network security
HSV kategori
Identifikatorer
URN: urn:nbn:se:bth-20512DOI: 10.1007/s00766-020-00338-wISI: 000570852900001Scopus ID: 2-s2.0-85091237223OAI: oai:DiVA.org:bth-20512DiVA, id: diva2:1472656
Ingår i projekt
SERT- Software Engineering ReThought, Knowledge Foundation
Merknad

open access

Tilgjengelig fra: 2020-10-02 Laget: 2020-10-02 Sist oppdatert: 2021-05-25bibliografisk kontrollert

Open Access i DiVA

fulltext(2741 kB)611 nedlastinger
Filinformasjon
Fil FULLTEXT01.pdfFilstørrelse 2741 kBChecksum SHA-512
9fe3d9ab9c8be6adb7545602652d105f56babdf3a17a5bbff0d4bf23f00131ff644173d9871656261874f16b7cd87a3c4d52afa3dcf4b97d51bc0d9241ad4c42
Type fulltextMimetype application/pdf

Andre lenker

Forlagets fulltekstScopus

Person

Mendez, Daniel

Søk i DiVA

Av forfatter/redaktør
Mendez, Daniel
Av organisasjonen
I samme tidsskrift
Requirements Engineering

Søk utenfor DiVA

GoogleGoogle Scholar
Totalt: 611 nedlastinger
Antall nedlastinger er summen av alle nedlastinger av alle fulltekster. Det kan for eksempel være tidligere versjoner som er ikke lenger tilgjengelige

doi
urn-nbn

Altmetric

doi
urn-nbn
Totalt: 155 treff
RefereraExporteraLink to record
Permanent link

Direct link
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annet format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annet språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf