• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Artikel
  4. Threat analysis in the software development lifecycle
 
  • Details
  • Full
Options
2014
Journal Article
Title

Threat analysis in the software development lifecycle

Abstract
Businesses and governments that deploy and operate IT (information technology) systems continue to seek assurance that software they procure has the security characteristics they expect. The criteria used to evaluate the security of software are expanding from static sets of functional and assurance requirements to complex sets of evidence related to development practices for design, coding, testing, and support, plus consideration of security in the supply chain. To meet these evolving expectations, creators of software are faced with the challenge of consistently and continuously applying the most current knowledge about risks, threats, and weaknesses to their existing and new software assets. Yet the practice of threat analysis remains an art form that is highly subjective and reserved for a small community of security experts. This paper reviews the findings of an IBM-sponsored project with the Fraunhofer Institute for Secure Information Technology (SIT) and the Technische Universität Darmstadt. This project investigated aspects of security in software development, including practical methods for threat analysis. The project also examined existing methods and tools, assessing their efficacy for software development within an open-source software supply chain. These efforts yielded valuable insights plus an automated tool and knowledge base that has the potential for overcoming some of the current limitations of secure development on a large scale.
Author(s)
Whitmore, Jim
IBM
Türpe, Sven
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
Triller, Stefan
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
Poller, Andreas
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
Carlson, Christina
IBM
Journal
IBM journal of research and development  
DOI
10.1147/JRD.2013.2288060
Language
English
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
Keyword(s)
  • secure software development

  • CWE database

  • process

  • tools

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024