作者
Daniela Soares Cruzes, Martin Gilje Jaatun, Karin Bernsmed, Inger Anne Tøndel
发表日期
2018/11/26
来源
2018 25th Australasian Software Engineering Conference (ASWEC)
页码范围
111-120
出版商
IEEE
简介
The goal of secure software engineering is to create software that keeps performing as intended even when exposed to attacks. Threat modeling is considered to be a key activity, but can be challenging to perform for developers, and even more so in agile software development. Hence, threat modeling has not seen widespread use in agile software projects. The goal of this paper is to investigate the challenges facing adoption of threat modeling using the Microsoft approach with STRIDE. We performed a case study in a company comprising five agile development projects. We identified 21 challenges to threat modeling that emerged from our observations. We then mapped these challenges to challenges found in the literature. Some challenges overlap the findings from the literature; the extra challenges we have found in our exploratory study came mostly from the activities of asset identification and also from our …
引用总数
20192020202120222023202483129115
学术搜索中的文章
DS Cruzes, MG Jaatun, K Bernsmed, IA Tøndel - 2018 25th Australasian Software Engineering …, 2018