Misuse for Security Hardening Assessment in Application Software Deployment

Kwanchanok Limbandit, Yunyong Teng-amnuay · International Journal of Future Computer and Communication · 2012

In software installation, the hardening status of the target system is difficult to assessed and usually depends on the expertise and care of system administrator. These non-functional requirements can be rendered functional by using misuses in misuse case diagram. This allows the assessment to be incorporated into the software design process and implemented as part of the deployment module. The assessment can thus be carried out automatically during software installation. As system hardening is mostly independent from software functionalities, the assessment can be expressed as design patterns to accommodate the design process. Four examples of system hardening were used: program and data memory separation, Mandatory Access Control (MAC), firewall, and logging.

Read the paper · More papers on PaperTik