A position study to investigate technical debt associated with security weaknesses
A position study to investigate technical debt associated with security weaknesses
复制标题
调查与安全弱点相关的技术债务的立场研究
DOI:
10.1145/3194164.3194167
复制
发表时间:
2018
期刊:
影响因子:
--
通讯作者:
Valentien, Tessa
中科院分区:
文献类型:
--
作者:
Izurieta, Clemente;Rice, David;Kimball, Kali;Valentien, Tessa
ContextManaging technical debt (TD) associated with potential security breaches found during design can lead to catching vulnerabilities (i.e., exploitable weaknesses) earlier in the software lifecycle; thus, anticipating TD principal and interest that can have decidedly negative impacts on businesses.GoalTo establish an approach to help assess TD associated with security weaknesses by leveraging the Common Weakness Enumeration (CWE) and its scoring mechanism, the Common Weakness Scoring System (CWSS).MethodWe present a position study with a five-step approach employing the Quamoco quality model to operationalize the scoring of architectural CWEs.ResultsWe use static analysis to detect design level CWEs, calculate their CWSS scores, and provide a relative ranking of weaknesses that help practitioners identify the highest risks in an organization with a potential to impact TD.ConclusionCWSS is a community agreed upon method that should be leveraged to help inform the ranking of security related TD items.