Experimental Evaluation of Security Requirements Engineering Benefits

Abstract

Security Requirements Engineering (SRE) approaches are designed to improve information system security by thinking about security requirements at the beginning of the software development lifecycle. This paper is a quantitative evaluation of the benefits of applying such an SRE approach. The followed methodology was to develop two versions of the same web application, with and without using SRE, then comparing the level of security in each version by running different test tools. The subsequent results clearly support the benefits of the early use of SRE with a 38% security improvement in the secure version of the application. This security benefit reaches 67% for high severity vulnerabilities, leaving only non-critical and easy-to-fix vulnerabilities.

Authors and Affiliations

Jaouad Boutahar, Ilham Maskani, Souhaïl El Ghazi El Houssaïni

Keywords

Related Articles

FRoTeMa: Fast and Robust Template Matching

Template matching is one of the most basic techniques in computer vision, where the algorithm should search for a template image T in an image to analyze I. This paper considers the rotation, scale, brightness and contra...

Quantifying Integrity Impacts in Security Risk Scoring Models

Organizations are attacked daily by criminal hackers. Managers need to know what kinds of cyber-attacks they are exposed to, for taking defense activities. Attackers may cause several kinds of damages according to the kn...

 An Intelligent Software Workflow Process Design for Location Management on Mobile Devices

  Advances in the technologies of networking, wireless communication and trimness of computers lead to the rapid development in mobile communication infrastructure, and have drastically changed information proc...

Virtual Reality Full Immersion Techniques for Enhancing Workers Performance, 20 years Later: A Review and a Reformulation

The principal aim of this article is to review and reformulate the work published by Alfaro-Casas, Bridi and Fialho [1], in 1997, about the use of virtual reality immersion techniques for enhancing workers performance’....

Characterization of Dynamic Bayesian Network-The Dynamic Bayesian Network as temporal network

In this report, we will be interested at Dynamic Bayesian Network (DBNs) as a model that tries to incorporate temporal dimension with uncertainty. We start with basics of DBN where we especially focus in Inference and L...

Download PDF file
  • EP ID EP417695
  • DOI 10.14569/IJACSA.2018.091158
  • Views 103
  • Downloads 0

How To Cite

Jaouad Boutahar, Ilham Maskani, Souhaïl El Ghazi El Houssaïni (2018). Experimental Evaluation of Security Requirements Engineering Benefits. International Journal of Advanced Computer Science & Applications, 9(11), 411-415. https://europub.co.uk/articles/-A-417695