Secure paradigm for web application development
Bipesh Raj Subedi, Abeer Alsadoon, P. W. C. Prasad, Amr Elchouemi · 2016
Security protection is usually thought to be a separate process in web application development phases but the external security protection mechanisms are not effective to control threats and vulnerabilities in web applications. As a consequence, researchers have realized security development should be an integral part of System Development Lifecycle of web applications. This article presents a universal secure paradigm which the web developers can apply in the development process to enhance the security features of web applications. The proposed paradigm is an extension to security development practices with agile methodology. It consists of three phases, i.e., inception, construction and transition. Inception can be mapped to analysis stage of traditional development life cycle process and transition refers to security assurance stage before deployment whereas construction phase is iterative process of security development.