Redefining Security Engineering

C. Rudolph, A. Fuchs
{"title":"Redefining Security Engineering","authors":"C. Rudolph, A. Fuchs","doi":"10.1109/NTMS.2012.6208773","DOIUrl":null,"url":null,"abstract":"For a long time, security was not in the focus of software engineering and system engineering processes. Only quite recently the situation has changed and security issues are now more and more integrated into concrete steps of the development process. Various approaches exist for the elicitation of security requirements, for threat modeling, for risk analysis, or for security testing. These different approaches are more-and-more adapted for practical use and become integrated parts of software development life-cycles. Nevertheless, they only support isolated steps in the process (e.g. security of code) or concentrate on particular types of requirements (e.g. for access control). The long-term goal for security engineering shall be the establishment of processes supporting all steps of the engineering process in an integrated way and to co-ordinate the contributions by different roles in this process. This paper identifies the different tasks of security engineering and discusses what parts of these tasks can be realised by using existing approaches. Further, three embedded scenarios are used to identify some concrete requirements for a security engineering process. This discussion shall show the scope of future research and developments in the area of security engineering and motivate inter-disciplinary approaches to establish security engineering as a research discipline.","PeriodicalId":401320,"journal":{"name":"2012 5th International Conference on New Technologies, Mobility and Security (NTMS)","volume":"21 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2012-05-07","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2012 5th International Conference on New Technologies, Mobility and Security (NTMS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/NTMS.2012.6208773","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

For a long time, security was not in the focus of software engineering and system engineering processes. Only quite recently the situation has changed and security issues are now more and more integrated into concrete steps of the development process. Various approaches exist for the elicitation of security requirements, for threat modeling, for risk analysis, or for security testing. These different approaches are more-and-more adapted for practical use and become integrated parts of software development life-cycles. Nevertheless, they only support isolated steps in the process (e.g. security of code) or concentrate on particular types of requirements (e.g. for access control). The long-term goal for security engineering shall be the establishment of processes supporting all steps of the engineering process in an integrated way and to co-ordinate the contributions by different roles in this process. This paper identifies the different tasks of security engineering and discusses what parts of these tasks can be realised by using existing approaches. Further, three embedded scenarios are used to identify some concrete requirements for a security engineering process. This discussion shall show the scope of future research and developments in the area of security engineering and motivate inter-disciplinary approaches to establish security engineering as a research discipline.
重新定义安全工程
很长一段时间以来,安全性都不是软件工程和系统工程过程的重点。直到最近局势才发生变化,安全问题现在越来越多地纳入发展进程的具体步骤。存在各种各样的方法来引出安全需求、进行威胁建模、进行风险分析或进行安全测试。这些不同的方法越来越适合于实际使用,并成为软件开发生命周期的集成部分。然而,它们只支持过程中孤立的步骤(例如代码的安全性)或集中于特定类型的需求(例如访问控制)。安全工程的长期目标应该是建立以集成的方式支持工程过程所有步骤的过程,并协调该过程中不同角色的贡献。本文确定了安全工程的不同任务,并讨论了这些任务的哪些部分可以通过使用现有方法来实现。此外,还使用了三个嵌入式场景来确定安全工程流程的一些具体需求。本讨论将展示安全工程领域未来研究和发展的范围,并激励跨学科方法将安全工程建立为一门研究学科。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信