ASSURE: automated support for secure and usable requirements engineering

  • Authors:
  • Jose Romero-Mariona;Hadar Ziv;Debra Richardson

  • Affiliations:
  • University of California, Irvine, Irvine, CA, USA;University of California, Irvine, Irvine, CA, USA;University of California, Irvine, Irvine, CA, USA

  • Venue:
  • Proceedings of the 19th international symposium on Software testing and analysis
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

Proper testing is an essential and critical part of any development effort. However, software testing is a complex undertaking, especially in the midst of today's security threats. Hackers, social engineering scams, and unaware users, are just a few potential threats that developers must consider not only during development, but more importantly during testing. There are significant reputation and financial losses related to security aspects that could have been addressed during requirements specification. While a variety of approaches to security requirements specification have been proposed, there is a tangible lack in the support that they offer during testing. In this paper we describe the tool support of a new security requirements engineering technique called SURE-Secure and Usable Requirements Engineering. ASSURE - Automated Support for Secure and Usable Requirements Engineering -, is a system developed to aid in the mapping of security requirements into testing artifacts. This support goes beyond mapping and aids also in the management of users and projects.