Towards Secure Software Engineering
L M Jayalath, K A C Dharshana, R M T P Rathnayake · South Asian Research Journal of Engineering and Technology · 2020
Software plays a major role in the present context.Therefore more and more software solutions are developed.These software solutions are hacked due to vulnerabilities available in the software.Most of these vulnerabilities are security-related.One of the key reasons behind this is the lack of security-related knowledge among the developers.Therefore it is important to assist them during the implementation stage.There are static analysis tools to assist them but these tools have a high concern on code quality and the architecture while having less attention for code security.Due to all these, it cost a lot during the maintenance phase to overcome the security-related issues.The suggested solution is a combination of three modules.Module one will rank the threats identified by the Microsoft Threat Modeling Tool in the design phase.Module two is an IntelliJ plugin which will assist the Java developers to maintain software security with respect to fifteen selected CERT guidelines.Module three will compare the design and the implementation while considering the inputs from the other two modules.