Analyzing risks at architectural level
Mati Ullah Khan, Mansoor Munib, Umar Manzoor, Samia Nefti‐Meziani · 2011
Conventional risk analysis techniques do not necessarily cover all security aspects in software. Defects in a software design cannot be identified by simply looking for flaws in the code. Therefore, carrying out risk analysis at architecture level is important. In this paper, we have performed architectural risk analysis of Chromium (which is an open source web browser project) and a custom developed small sized web service. The method followed to carry out the analysis is a best practice approach described by Gary McGraw in his book Software Security: Building Security In.