Vulnerability and Risk Analysis Methods and Application in Large Scale Development of Secure Systems
Shanai Ardi · Linköping studies in science and technology. Dissertations · 2020
Since software products are heavily used in today's connected society, design and implementation of such software products to make them resilient to security threats become crucial.This thesis addresses some of the challenges faced by software vendors when developing secure software.The approach is to reduce the risk of introducing security weaknesses to software products by providing solutions that support software developers during the software lifecycle.Software developers are usually not security experts.However, there are methods and tools, such as the ones introduced in this thesis, that can help developers build more secure software.The research is performed with a design science approach, where the risk reducing method is the artifact that is iteratively developed.Chronologically, the research is divided into two parts.The first part provides security models as a means of developing a detailed understanding of the extent of potential security issues and their respective security mitigation activities.The purpose is to lower the risk of introducing vulnerabilities to the software during its lifecycle.This is facilitated by the Sustainable Software Security Process (S3P), which is a structured and generally applicable process aimed at minimizing the effort of using security models during all phases of the software development process.S3P achieves this in three steps.The first step uses a semi-formal modeling approach and identifies causes of known vulnerabilities in terms of defects and weaknesses in development activities that may introduce the vulnerability in the code.The second step identifies measures that if in place would address the causes and eliminate the underlying vulnerability and support selection of the most suitable measures.The final step ensures that the selected measures are adopted into the development process to reduce the risk of having similar vulnerabilities in the future. vii Populärvetenskaplig sammanfattningMed tanke på att programvaruprodukter i stor utsträckning används i dagens uppkopplade samhälle är det absolut nödvändigt att utforma och implementera sådana programvaruprodukter för att vara motståndskraftiga mot säkerhetshot.Denna avhandling presenterar forskning som tar itu med några av de säkerhetsutmaningar som programvaruleverantörer står inför.Tillvägagångssättet är att minska risken för att säkerhetsbrister i programvaruprodukter överhuvudtaget införs genom att tillhandahålla stöd för programvaruutvecklare under programvarans hela livscykel.De flesta programvaruutvecklare är vanligtvis inte säkerhetsexperter.Det finns dock metoder och verktyg, likt de som beskrivs i denna avhandling, som kan hjälpa utvecklare att bygga säkrare programvara.Forskningen genomfördes med en "design science" metod där vi gradvis byggde, prövade och förfinade vår metod för att upptäcka och hantera säkerhetsrisker.Kronologiskt är forskningen uppdelad i två delar.Den första delen tillhandahåller säkerhetsmodeller som medel för att utveckla en detaljerad förståelse för omfattningen av potentiella säkerhetsproblem och deras respektive motåtgärder.Syftet är att minska risken för att programvarusårbarheter introduceras i programvaran någon gång under dess livscykel.Detta görs med hjälp av S3P (Sustainable Software Security Process) som är en strukturerad och generellt tillämpbar process som syftar till att minimera arbetet med att använda säkerhetsmodeller under alla faser av programutvecklingsprocessen.Forskningsbidragen omfattar både stöd för att bygga säkerhetsmodeller av hot och hur hoten och deras motmedel hänger ihop.När väl motmedel är definierade byggs en process som garanterar att motmedlen ändvänds.Detta kompletteras med metoder och verktyg för att integrera processen med befintliga utvecklingsmetoder.Division for Database and Information Techniques (ADIT) at the Department of Computer and Information Science at Linköping University, and then paused it in 2011 when I joined Ericsson as a full