Current Taxonomy of Information Security Threats in Software Development Life Cycle

Alexander Barabanov, Alexey S. Markov, Maksim I. Grishin, Valentin L. Tsirlov · 2018

The work presents the original taxonomy of information security threats in the software development life cycle. The model of an attacker acting in software development environments is presented. The proposed attacker model contains: a list of sources of information security threats, attacker types and categories, description of likely targets (motivations) of attacks on information security and description of attackers' potentials and capabilities. A systematized list of information security threats during software development (35 threats) was proposed. Threats were classified according with software life cycle processes established by ISO/IEC 12207. Each threat is presented using the following parameters: threat description, threat sources, target, and security implications. Comparative analysis of the obtained list of information security threats and current research findings was carried out.

Read the paper · More papers on PaperTik