Measuring Security: A Step Towards Enhancing Security of System
Shruti Jaiswal and
Daya Gupta
Additional contact information
Shruti Jaiswal: Department of Computer Science and Engineering, Delhi Technological University, Delhi, India
Daya Gupta: Department of Computer Science and Engineering, Delhi Technological University, Delhi, India
International Journal of Information Systems in the Service Sector (IJISSS), 2018, vol. 10, issue 1, 28-53
Abstract:
The researchers have been focusing on embedding security from the early phases of software development lifecycle. They have researched and innovated a field of Security Engineering where security concerns are embedded during requirement, design, and testing phases of software development. Efforts were made in developing methods, methodologies, and tools to handle security issues. Various methods are present in the literature for eliciting, analyzing and prioritizing the security requirements. During the design phase based on prioritized requirements, environment parameters and attribute a suitable security algorithm mainly cryptography algorithms are identified. Then a question arises how to test the effectiveness of chosen algorithm? Therefore, as an answer to the issue in this paper, a process for Security Testing is presented that evaluates the selected security algorithms. Evaluation is done by generating the test scenarios for functionalities using sequence diagram representing the threats at vulnerable points. Then, checking the mitigation of potential threats at identified vulnerable points. A security index is generated which shows the effectiveness of deployed/ chosen security algorithm. The process ends with the generation of a test report depicting the testing summary. For a clear understanding of the process, the proposal is illustrated with a case study of the cloud storage as a service model.
Date: 2018
References: Add references at CitEc
Citations:
Downloads: (external link)
http://services.igi-global.com/resolvedoi/resolve. ... 18/IJISSS.2018010103 (application/pdf)
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:igg:jisss0:v:10:y:2018:i:1:p:28-53
Access Statistics for this article
International Journal of Information Systems in the Service Sector (IJISSS) is currently edited by John Wang
More articles in International Journal of Information Systems in the Service Sector (IJISSS) from IGI Global
Bibliographic data for series maintained by Journal Editor ().