• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Buch
  4. Progress report on the experimental evaluation of security inspection guidance
 
  • Details
  • Full
Options
2009
Report
Title

Progress report on the experimental evaluation of security inspection guidance

Abstract
Although security inspections have proven to be a very efficient means for assuring software security early in the software development lifecycle, they are not used extensively because they usually need to be performed by security experts, who are few and thus expensive. Adoption of security inspections could be facilitated if one could encapsulate the expertise and experience of security experts as guidance for security inspections performed by software developers. Our approach to addressing this challenge consists of two different kinds of reading support that provide the required guidance to software developers: Vulnerability Inspection Diagram (VID) and Security Inspection Scenario (SIS). In this article, we sketch our initial experimental evaluation of VIDs and SIS with a group of software developers of an industrial project partner. We present the setup and the experiment's results. In addition, we describe the implications of our results on future work regarding the approach and further evaluation.
Author(s)
Elberzhager, Frank  
Jawurek, Marek
Jung, Christian  
Klaus, Alexander  
Publishing Place
Kaiserslautern
DOI
10.1109/ESEM.2009.5314239
Language
English
Fraunhofer-Institut für Experimentelles Software Engineering IESE  
Keyword(s)
  • SHIELDS

  • security

  • inspection

  • reading technique

  • experiment

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024