Quantifying Satisfaction of Security Requirements of Cloud Software Systems
المؤلف | Nhlabatsi, Armstrong |
المؤلف | Khan, Khaled MD |
المؤلف | Hong, Jin B. |
المؤلف | Kim, Dong Seong |
المؤلف | Fernandez, Rachael |
المؤلف | Fetais, Noora |
تاريخ الإتاحة | 2024-03-10T05:42:08Z |
تاريخ النشر | 2023 |
اسم المنشور | IEEE Transactions on Cloud Computing |
المصدر | Scopus |
الرقم المعياري الدولي للكتاب | 21687161 |
الملخص | The satisfaction of a software requirement is commonly stated as a Boolean value, that is, a security requirement is either satisfied (true) or not (false). However, a discrete Boolean value to measure the satisfaction level of a security requirement by deployed mechanisms is not very useful. Rather, it would be more effective if we could quantify the level of satisfaction of security requirements on a continuous scale. We propose an approach to achieve this for cloud software systems based on relationships between defense strength, exploitability of vulnerabilities, and attack severity. We extend the concept of entailment relationship from the field of requirements engineering with the satisfiability aspects of security requirements. The proposed approach enables us to systematically structure security concepts into three sets of related descriptions to quantify the satisfaction level of security requirements with the deployed security solutions. To demonstrate the feasibility of the proposed approach, we evaluate the approach in a case study. As a result, security administrators are able to deploy more effective and appropriate security solutions based on their assessment. |
راعي المشروع | This article was made possible by Grant NPRP 8-531-1-111 from Qatar National Research Fund (QNRF) |
اللغة | en |
الناشر | Institute of Electrical and Electronics Engineers Inc. |
الموضوع | Cloud computing entailment relationship security quantification security requirements |
النوع | Article |
الصفحات | 426-444 |
رقم العدد | 1 |
رقم المجلد | 11 |
الملفات في هذه التسجيلة
الملفات | الحجم | الصيغة | العرض |
---|---|---|---|
لا توجد ملفات لها صلة بهذه التسجيلة. |
هذه التسجيلة تظهر في المجموعات التالية
-
علوم وهندسة الحاسب [2402 items ]
-
الشبكات وخدمات البنية التحتية للمعلومات والبيانات [70 items ]