Vis enkel innførsel

dc.contributor.authorKatt, Basel
dc.contributor.authorPrasher, Nishu
dc.date.accessioned2020-04-03T10:19:20Z
dc.date.available2020-04-03T10:19:20Z
dc.date.issued2018
dc.identifier.citationECSA '18: Proceedings of the 12th European Conference on Software Architecture: Companion Proceedings, September 2018, Article No.: 59, 1–7en_US
dc.identifier.urihttps://hdl.handle.net/11250/2650277
dc.description.abstractSecurity assurance is the confidence that a system meets its security requirements based on specific evidences that an assurance technique provide. The notion of measuring security is complex and tricky. Existing approaches either (1) consider one aspect of assurance, like security requirements fulfillment, or threat/vulnerability existence, or (2) do not consider the relevance of the different security requirements to the evaluated application context. Furthermore, they are mostly qualitative in nature and are heavily based on manual processing, which make them costly and time consuming. Therefore, they are not widely used and applied, especially by small and medium-sized enterprises (SME), which constitute the backbone of the Norwegian economy. In this paper, we propose a quantification method that aims at evaluating security assurance of systems by measuring (1) the level of confidence that the mechanisms fulfilling security requirements are present and (2) the vulnerabilities associated with possible security threats are absent. Additionally, an assurance evaluation process is proposed. Two case studies applying our method are presented. The case studies use our assurance method to evaluate the security level of two REST APIs developed by Statistics Norway, where one of the authors is employed. Analysis shows that the API with the most security mechanisms implemented got a slightly higher security assurance score. Security requirement relevance and vulnerability impact played a role in the overall scores.en_US
dc.language.isoengen_US
dc.publisherACM (Association for Computing Machinery)en_US
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 Internasjonal*
dc.rights.urihttp://creativecommons.org/licenses/by-nc-nd/4.0/deed.no*
dc.titleQuantitative security assurance metrics: REST API case studiesen_US
dc.typeTidsskriftartikkelen_US
dc.description.versionacceptedVersionen_US
dc.subject.nsiVDP::Teknologi: 500::Informasjons- og kommunikasjonsteknologi: 550::Datateknologi: 551en_US
dc.source.pagenumber1-7en_US
dc.source.journalECSA '18: Proceedings of the 12th European Conference on Software Architecture: Companion Proceedingsen_US
dc.identifier.doihttps://doi.org/10.1145/3241403.3241464


Tilhørende fil(er)

Thumbnail

Denne innførselen finnes i følgende samling(er)

Vis enkel innførsel

Attribution-NonCommercial-NoDerivatives 4.0 Internasjonal
Med mindre annet er angitt, så er denne innførselen lisensiert som Attribution-NonCommercial-NoDerivatives 4.0 Internasjonal