Environment-driven threats elicitation for web applications

  • Authors:
  • Hui Guan;Weiru Chen;Lin Liu;Hongji Yang

  • Affiliations:
  • Shenyang University of Chemical Technology and Software Technology Research Laboratory, De Montfort University, Leicester, England;Shenyang University of Chemical Technology;School of Software, Tsinghua University, Beijing, China;Software Technology Research Laboratory, De Montfort University, Leicester, England

  • Venue:
  • KES-AMSTA'11 Proceedings of the 5th KES international conference on Agent and multi-agent systems: technologies and applications
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

The popularity and complexity of web application present challenges to the security implementation for web engineering. Threat elicitation is an indispensable step for developers to identify the possible threats to the web applications in the early phase of software development. In this context, a novel approach is proposed to ease the threats elicitation for web application by using a defined web application classification as the sieve to sift a common threat list. The final result shows that the proposed model is a simplified and effective solution to threats elicitation to web application.