首页> 外文会议>International Conference on Technical Debt >A Position Study to Investigate Technical Debt Associated with Security Weaknesses
【24h】

A Position Study to Investigate Technical Debt Associated with Security Weaknesses

机译:调查与安全漏洞相关的技术债务的职位研究

获取原文

摘要

Context: Managing technical debt (TD) associated with potential security breaches found during design can lead to catching vulnerabilities (i.e., exploitable weaknesses) earlier in the software lifecycle; thus, anticipating TD principal and interest that can have decidedly negative impacts on businesses. Goal: To establish an approach to help assess TD associated with security weaknesses by leveraging the Common Weakness Enumeration (CWE) and its scoring mechanism, the Common Weakness Scoring System (CWSS). Method: We present a position study with a five-step approach employing the Quamoco quality model to operationalize the scoring of architectural CWEs. Results: We use static analysis to detect design level CWEs, calculate their CWSS scores, and provide a relative ranking of weaknesses that help practitioners identify the highest risks in an organization with a potential to impact TD. Conclusion: CWSS is a community agreed upon method that should be leveraged to help inform the ranking of security related TD items.
机译:背景:管理与设计期间发现的潜在安全漏洞相关的技术债务(TD)可以导致在软件生命周期的早期捕获漏洞(即,可利用的漏洞);因此,预计可能会对业务产生负面影响的TD本金和利息。目标:利用通用弱点枚举(CWE)及其评分机制通用弱点评分系统(CWSS),建立一种方法来帮助评估与安全弱点相关的TD。方法:我们使用Quamoco质量模型通过五步方法介绍了一项职位研究,以对建筑CWE的评分进行操作。结果:我们使用静态分析来检测设计级别的CWE,计算其CWSS得分,并提供相对弱点排名,以帮助从业人员识别组织中可能影响TD的最高风险。结论:CWSS是社区同意的方法,应利用该方法来帮助告知与安全相关的TD项目的排名。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号