论文标题

SDLC中的风险评估,威胁建模和安全测试

Risk Assessment, Threat Modeling and Security Testing in SDLC

论文作者

Kamal, Alya Hannah Ahmad, Yen, Caryn Chuah Yi, Hui, Gan Jia, Ling, Pang Sze, Fatima-tuz-Zahra

论文摘要

软件开发过程被认为是创建上述软件的关键准则之一,对于提供更有效但令人满意的输出而言,这种方法是必要的。如果不将工作分为不同的阶段,则可能导致项目过程的许多延迟和效率低下,在这种过程中,这种混乱会直接影响产品质量和可靠性。此外,由于这种方法是任何项目的标准,因此由于缺乏意识而导致的安全涉及到安全性。因此,这项研究的目的是确定并阐述对软件开发过程中的安全性以及相关个人角色集成的安全性的发现和理解,以确保保持这种安全性。通过对文献的彻底分析和审查,通过本文做出了一项努力,以展示正确的过程以及确保软件开发过程的方法。同时,已经讨论了与该主题有关的某些问题以及提出适当的解决方案。此外,对诸如安全测试,风险评估,威胁建模和其他能够在软件开发过程中创建更安全的环境和系统方法等方法等方法进行了深入的讨论。

The software development process is considered as one of the key guidelines in the creation of said software and this approach is necessary for providing a more efficient yet satisfactory output. Without separation of work into distinct stages, it may lead to many delays and inefficiency of the project process where this disorganization can directly affect the product quality and reliability. Moreover, with this methodology established as the standard for any project, there are bound to be missteps specifically in regard to the involvement of security due to the lack of awareness. Therefore, the aim of this research is to identify and elaborate the findings and understanding of the security integrated into the process of software development as well as the related individual roles in ensuring that this security is maintained. Through thorough analysis and review of literature, an effort has been made through this paper to showcase the correct processes and ways for securing the software development process. At the same time, certain issues that pertain to this subject have been discussed together with proposing appropriate solutions. Furthermore, in depth discussion is carried out regarding methods such as security testing, risk assessment, threat modeling and other techniques that are able to create a more secure environment and systematic approach in a software development process.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源