Algorithmic Approach for Development of Misuse Case Modeling Framework for iMACOQR Metrics

Capt. Usha Banerjee, Arpita Banerjee, P. D. Murarka · International Conference on Advanced Computing · 2015

Since the beginning of the Information Technology age, the software organizations have conventionally focused on the improvement of quality of the code for refining and enhancing the security of software. From the studies carried out, practically, the improvement in code quality has proved to have least effect on the overall refinement, enhancement & implementation of security in software. It is a well-known fact that if measurement could not be drawn, the process could not be improved. Debate has been going on between the researcher, world over, on the need to identify and quantify the security aspect of the software while it is still in its initial stages of development. So far, industry has supported and validated the work done by the researchers. Although a significant contribution has been made, still, the quantification of software security is in its infancy and a lot of scope exists. Security should be implemented during the software development process 'right from the beginning'. Apart from other available techniques for the measurement of software security, misuse cases and abuse cases are some of the modeling techniques which could be applied to incorporate security requirements during the early stages of software development process. Subsequently, measure could be drawn from such security requirements and used for further analysis leading to the improvement in the software process. In this paper, we propose an algorithmic approach to classify misuse cases with their respective use cases to develop a framework which could be potentially & practically applied to identify and quantify the patterns of the defect in the misuse case modeling using iMACOQR (improvised Misuse and Abuse Case Oriented Quality Requirements) metrics. The measures and ratios thus obtained may help the security engineering team to plan eliminate defects of misuse case modeling during the requirements engineering phase. The results obtained from the use of iMACOQR (improvised Misuse and Abuse Case Oriented Quality Requirements) metrics may support the cause of designing and developing secured software.

Read the paper · More papers on PaperTik