论文标题

具有两个步幅变体的受控实验的复制

A replication of a controlled experiment with two STRIDE variants

论文作者

Mbaka, Winnie, Tuma, Katja

论文摘要

为了避免在软件部署后昂贵的安全补丁,组织中采用安全性安全技术(例如,步幅威胁分析)在实施系统之前将安全性问题扎根。尽管网络安全劳动力的全球差距以及进行威胁分析所需的高度手动努力,但组织仍在加强威胁分析活动。但是,过去的实验结果在某些威胁分析技术的绩效指标上尚无定论,因此从业人员几乎没有选择采用该技术的证据。为了解决这个问题,我们复制了一项受控实验。我们的研究旨在测量和比较两个步幅变体(元素和相互作用)的性能指标(生产力和精度)。我们通过将结果与原始研究进行比较来结束论文。

To avoid costly security patching after software deployment, security-by-design techniques (e.g., STRIDE threat analysis) are adopted in organizations to root out security issues before the system is ever implemented. Despite the global gap in cybersecurity workforce and the high manual effort required for performing threat analysis, organizations are ramping up threat analysis activities. However, past experimental results were inconclusive regarding some performance indicators of threat analysis techniques thus practitioners have little evidence for choosing the technique to adopt. To address this issue, we replicated a controlled experiment with STRIDE. Our study was aimed at measuring and comparing the performance indicators (productivity and precision) of two STRIDE variants (element and interaction). We conclude the paper by comparing our results to the original study.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源