Asset Details
MbrlCatalogueTitleDetail
Do you wish to reserve the book?
An efficient approach for reviewing security-related aspects in agile requirements specifications of web applications
by
Mendez, Daniel
, Villamizar Hugo
, Kalinowski Marcos
, Garcia, Alessandro
in
Applications programs
/ Defects
/ Natural language processing
/ Requirements specifications
/ Reviewing
/ Security
/ Software
/ Software development
2020
Hey, we have placed the reservation for you!
By the way, why not check out events that you can attend while you pick your title.
You are currently in the queue to collect this book. You will be notified once it is your turn to collect the book.
Oops! Something went wrong.
Looks like we were not able to place the reservation. Kindly try again later.
Are you sure you want to remove the book from the shelf?
An efficient approach for reviewing security-related aspects in agile requirements specifications of web applications
by
Mendez, Daniel
, Villamizar Hugo
, Kalinowski Marcos
, Garcia, Alessandro
in
Applications programs
/ Defects
/ Natural language processing
/ Requirements specifications
/ Reviewing
/ Security
/ Software
/ Software development
2020
Oops! Something went wrong.
While trying to remove the title from your shelf something went wrong :( Kindly try again later!
Do you wish to request the book?
An efficient approach for reviewing security-related aspects in agile requirements specifications of web applications
by
Mendez, Daniel
, Villamizar Hugo
, Kalinowski Marcos
, Garcia, Alessandro
in
Applications programs
/ Defects
/ Natural language processing
/ Requirements specifications
/ Reviewing
/ Security
/ Software
/ Software development
2020
Please be aware that the book you have requested cannot be checked out. If you would like to checkout this book, you can reserve another copy
We have requested the book for you!
Your request is successful and it will be processed during the Library working hours. Please check the status of your request in My Requests.
Oops! Something went wrong.
Looks like we were not able to place your request. Kindly try again later.
An efficient approach for reviewing security-related aspects in agile requirements specifications of web applications
Journal Article
An efficient approach for reviewing security-related aspects in agile requirements specifications of web applications
2020
Request Book From Autostore
and Choose the Collection Method
Overview
Defects in requirement specifications can have severe consequences during the software development life cycle. Some of them may result in poor product quality and/or time and budget overrun due to incorrect or missing quality characteristics, such as security. This characteristic requires special attention in web applications because they have become a target for manipulating sensible data. Several concerns make security difficult to deal with. For instance, security requirements are often misunderstood and improperly specified due to lack of security expertise and emphasis on security during early stages of software development. This often leads to unspecified or ill-defined security-related aspects. These concerns become even more challenging in agile contexts, where lightweight documentation is typically produced. To tackle this problem, we designed an approach for reviewing security-related aspects in agile requirements specifications of web applications. Our proposal considers user stories and security specifications as inputs and relates those user stories to security properties via natural language processing. Based on the related security properties, our approach identifies high-level security requirements from the Open Web Application Security Project (OWASP) to be verified and generates a reading technique to support reviewers in detecting defects. We evaluate our approach via three experimental trials conducted with 56 novice software engineers, measuring effectiveness, efficiency, usefulness and ease of use. We compare our approach against using: (1) the OWASP high-level security requirements and (2) a perspective-based approach as proposed in contemporary state of the art. The results strengthen our confidence that using our approach has a positive impact (with large effect size) on the performance of inspectors in terms of effectiveness and efficiency.
Publisher
Springer Nature B.V
This website uses cookies to ensure you get the best experience on our website.