Comparative Evaluation of Architectural and Code-Level Approaches for Finding Security Vulnerabilities
Radu Vanciu, Ebrahim Khalaj, Marwan Abi-Antoun · 2014
During architectural risk analysis, Security Information Workers (SIWs) reason about security-relevant architectural flaws using a high-level representation of the system's structure instead of directly reading the code as in during a code review. It is still hard to extract from the code a high-level representation that is sound, conveys design intent, and enables expressive constraints that can find security vulnerabilities. As a result, architecture-level approaches are less mature than code-level ones that extract low-level representations that are not directly intended for use by SIWs.