Security Requirements Specification: A Formal Method Perspective

Aditya Dev Mishra, Khurram Mustafa · 2020

In the last few years, the field of software security requirements have changed radically. The security requirements specification is now broadly recognized, and among the actively pursued research challenges in both software engineering communities and security assurance communities. Security is an essential aspect of software quality nowadays, in view of criticality and ever-increasing presence all the way. Many quality and reliability oriented software processes omit or at least postpone it to take it as an after-thought activity. The scope of security requirements problems are not limited to the security, but extend its effect to the whole software life cycle. Almost 50% of security problems originate in this phase and culminate into inadequate/inaccurate specifications; lead to huge fixing-efforts and cost enormously. Therefore, there is a need to specify the security requirement more precisely, consistently and adequately to avoid such problems. Realizing the advantage of the formal methods, we propose a framework for security requirement specification by formal methods. The objective of the proposed framework is to specify the security requirements formally and integrate the same with SDLC. The main goal of the proposed framework to assist security engineers about classification, elicitation, and specification of security requirements precisely, systematic and unambiguously during the requirement engineering process.

Read the paper · More papers on PaperTik