Loading [MathJax]/extensions/MathMenu.js
Attack Surface Identification and Reduction Model Applied in Scrum | IEEE Conference Publication | IEEE Xplore

Attack Surface Identification and Reduction Model Applied in Scrum


Abstract:

Today's software is full of security vulnerabilities that invite attack. Attackers are especially drawn to software systems containing sensitive data. For such systems, t...Show More

Abstract:

Today's software is full of security vulnerabilities that invite attack. Attackers are especially drawn to software systems containing sensitive data. For such systems, this paper presents a modeling approach especially suited for Serum or other forms of agile development to identify and reduce the attack surface. The latter arises due to the locations containing sensitive data within the software system that are reachable by attackers. The approach reduces the attack surface by changing the design so that the number of such locations is reduced. The approach performs these changes on a visual model of the software system. The changes are then considered for application to the actual system to improve its security.
Date of Conference: 03-04 June 2019
Date Added to IEEE Xplore: 31 October 2019
ISBN Information:
Conference Location: Oxford, UK

Contact IEEE to Subscribe

References

References is not available for this document.