Analyzing risks at architectural level

Analyzing risks at architectural level
复制标题

在架构层面分析风险

DOI:
--
复制
发表时间:
2011
期刊:
International Conference on Information Society
影响因子:
--
通讯作者:
S. Nefti
S. Nefti
中科院分区:
--
文献类型:
--
作者:
Mati Ullah Khan;Mansoor Munib;U. Manzoor;S. Nefti

文献摘要

被引文献

相似文献

常规风险分析技术不一定涵盖软件中的所有安全方面。软件设计中的缺陷无法通过简单地寻找代码中的缺陷来识别。因此,在建筑层面进行风险分析很重要。在本文中,我们对Chromium(这是一个开源Web浏览器项目)和定制开发的小型Web服务进行了建筑风险分析。进行分析的方法是加里·麦格劳(Gary McGraw)在他的书软件安全性:建立安全性中描述的最佳实践方法。
Conventional risk analysis techniques do not necessarily cover all security aspects in software. Defects in a software design cannot be identified by simply looking for flaws in the code. Therefore, carrying out risk analysis at architecture level is important. In this paper, we have performed architectural risk analysis of Chromium (which is an open source web browser project) and a custom developed small sized web service. The method followed to carry out the analysis is a best practice approach described by Gary McGraw in his book Software Security: Building Security In.