Complexity Measures for Secure Service-Oriented Software Architectures

  • Authors:
  • Yanguo (Michael) Liu;Issa Traore

  • Affiliations:
  • University of Victoria, Canada;University of Victoria, Canada

  • Venue:
  • PROMISE '07 Proceedings of the Third International Workshop on Predictor Models in Software Engineering
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

As software attacks become widespread, the ability for a software system to resist malicious attacks has become a key concern in software quality engineering. Software attackability is a concept proposed recently in the research literature to measure the extent to which a software system or service could be the target of successful attacks. Like most external attributes, attackability is to some extent disconnected from the internal of software products. To mitigate software attackability, we need to identify and manipulate related internal software attributes. Our goal in this paper is to study software complexity as one such internal attribute. We apply the User System Interaction Effect (USIE) model, a security measurement abstraction paradigm proposed in previous research, to define and validate a sample metric for service complexity. We thereby establish the usefulness of our sample metric through empirical investigation using open source software system as target application.