SECURITY MEASUREMENT BASED ON GQM TO IMPROVE APPLICATION SECURITY DURING REQUIREMENTS STAGE
Ala A. Abdulrazeg, Nurlida Basir Norita Md Norwawi · International Journal of Cyber-Security and Digital Forensics · 2012
Web applications are employed in a wide variety of contexts to support many daily social activities. Unfortunately, the tremendous rise in online applications has been accompanied by a proportional rise in the number and type of attacks against them. Web applications are continuously reported to be vulnerable to attacks and compromises. According to a recent analysis conducted by Symantec Inc [1], vulnerabilities and security breaches on enterprises are increasing, with web application attacks continuing to be a favoured attack vector. Furthermore, a report by WhiteHat security has found that 8 out of 10 web applications are vulnerable [2]. These reports indicate that even present-day web applications are not free from vulnerabilities. In security engineering, vulnerabilities result from defects or weaknesses that are inadvertently introduced at the design and implementation stages of the development life cycle that can be exploited by attackers to harm the application and its asset [3]. Therefore, security needs to be considered and measured from the early stage of the development life cycle.