Analyzing risks at architectural level
Analyzing risks at architectural level
复制标题
在架构层面分析风险
DOI:
--
复制
发表时间:
2011
期刊:
影响因子:
--
通讯作者:
S. Nefti
中科院分区:
文献类型:
--
作者:
Mati Ullah Khan;Mansoor Munib;U. Manzoor;S. Nefti
Conventional risk analysis techniques do not necessarily cover all security aspects in software. Defects in a software design cannot be identified by simply looking for flaws in the code. Therefore, carrying out risk analysis at architecture level is important. In this paper, we have performed architectural risk analysis of Chromium (which is an open source web browser project) and a custom developed small sized web service. The method followed to carry out the analysis is a best practice approach described by Gary McGraw in his book Software Security: Building Security In.