• No results found

Efficiency and Automation in Threat Analysis of Software Systems

N/A
N/A
Protected

Academic year: 2021

Share "Efficiency and Automation in Threat Analysis of Software Systems"

Copied!
1
0
0

Loading.... (view fulltext now)

Full text

(1)

Efficiency and Automation in

Threat Analysis of Software

Systems

Katja Tuma

Katja T

uma

Software systems are constantly under threat from cyber-attacks. To pro-tect their software, organizations design blueprints of future software and scrutinize them for security holes, even before any line of code written. Usually, this thorough analysis is performed manually by security experts, who strive to find as many issues as possible. However, due to resource constraints, only the most critical issues will be addressed. Not only is this way of working time-consuming, but it also leads analysts to discuss less important issues while possibly overlooking other critical issues. Further, even when analysts do find critical issues and require countermeasures to be put in place, there is no guarantee that the software developers will implement the security defenses as planned.

This thesis contributes to solving these problems. First, we improve an existing manual technique which enables the analysts to identify twice as many critical issues in our case studies. Second, we propose two tech-niques that detect security design flaws automatically and help in reducing the number of overlooked issues. Finally, we introduce a semi-automated approach to link the intended design to the implemented constructs and automatically verify that the implementation complies with the planned security requirements.

Katja Tuma

Department of Computer Science and Engineering

Software Engineering Division

2021 ISBN 978-91-8009-154-1

Efficiency and Automation in Threat Analysis of Software Systems

DEPARTMENT OF COMPUTER

SCIENCE AND ENGINEERING

DOCTORAL

THESIS

DOCTORAL THESIS

IT FACULTY

References

Related documents

46 Konkreta exempel skulle kunna vara främjandeinsatser för affärsänglar/affärsängelnätverk, skapa arenor där aktörer från utbuds- och efterfrågesidan kan mötas eller

The increasing availability of data and attention to services has increased the understanding of the contribution of services to innovation and productivity in

Närmare 90 procent av de statliga medlen (intäkter och utgifter) för näringslivets klimatomställning går till generella styrmedel, det vill säga styrmedel som påverkar

• Utbildningsnivåerna i Sveriges FA-regioner varierar kraftigt. I Stockholm har 46 procent av de sysselsatta eftergymnasial utbildning, medan samma andel i Dorotea endast

Den förbättrade tillgängligheten berör framför allt boende i områden med en mycket hög eller hög tillgänglighet till tätorter, men även antalet personer med längre än

Based on the possible attacks which can be done on embedded systems and the result of the CVE analysis done by Papp et al., we decided to focus on a set of vulnerabilities which

Especially regarding Orange’s novel, the concept of Native survivance sheds light on the representation of colonial trauma, since creating a narrative to represent the experience of

Industrial Emissions Directive, supplemented by horizontal legislation (e.g., Framework Directives on Waste and Water, Emissions Trading System, etc) and guidance on operating