Security by design: teaching secure software design and development techniques
John W. McManus · Journal of computing sciences in colleges · 2018
This paper is the first paper in a series of papers that describe the development of a Security by Design approach for teaching secure software design and development techniques. The focus of this paper is the design and development of the formal model for Internet of Things systems. Following papers will discuss proposed methods for incorporating the formal model and design and testing techniques into the core computer science curriculum and the results of student's research projects. The approach has been piloted with undergraduate students developing Internet of Things systems. The approach includes a formal model for Internet of Things systems; a set of design, development, and analysis tools and techniques; secure software development practices; and security testing practices. The goal of the design and analysis tools is to advance the students' knowledge of design patterns for Internet of Things systems and to and highlight potential cybersecurity and performance issues early in the design process. The techniques have been taught across a three-semester sequence of courses; Software Development; Introduction to Cybersecurity; and Secure Software Development. The techniques have been applied by undergraduate students developing several prototype Internet of Things research projects. The results gained from the student projects developed during the pilot period are being used to evaluate the effectiveness of the course materials and tools and techniques; and to guide future tool and curriculum development.