Security Requirements Engineering; State of the Art and Research Challenges

Mohammad Ali Hadavi, V. S. Hamishagi, H. M. Sangchi · 2008

Abstract — In recent years software has faced a new challenge called security. The new idea in software security which has attracted the world’s attention is to keep security in mind during development process. As requirements analysis plays an infrastructural role in this process, software security requirements would naturally be considered fundamental in secure software development. Stating peculiarities and deficiencies in security requirements engineering, this paper draws a picture from the current research situation by reviewing and classifying the efforts into four main categories; security requirements in the standard software development processes, security requirements engineering consist of eliciting and modeling security requirements, and threat modeling as a basis for security requirements engineering. Presenting challenges and open problems for each category, the paper will then set forth the research outlooks and future directions in security requirements. Index Terms—requirements engineering, security, software development process, threat modeling. functions are performed. Security is considered as a non-functional requirement. In recent years, tremendous growth in networks from one side and importance of information from the other side has contributed heavily to the importance of security requirements (SR). Adding security to software requirements indicates that security has been considered from the very first step of software development. SR objectives can be categorized as authentication, authorization, integrity, intrusion detection, non-repudiation, confidentiality and auditing [29]. This paper is organized into six sections. The next section discusses research issues in the context of SR. The third section points where SR stand in software development process. SR eliciting and modeling discuss in the forth section. Fifth section details the relationship between threat modeling and risk management. Concluding the discussions, the sixth section will describe the available gaps and research trends in this field. I.

Read the paper · More papers on PaperTik