TUHH Open Research
Help
  • Log In
    New user? Click here to register.Have you forgotten your password?
  • English
  • Deutsch
  • Communities & Collections
  • Publications
  • Research Data
  • People
  • Institutions
  • Projects
  • Statistics
  1. Home
  2. TUHH
  3. Publication References
  4. Two architectural threat analysis techniques compared
 
Options

Two architectural threat analysis techniques compared

Publikationstyp
Conference Paper
Date Issued
2018-09
Sprache
English
Author(s)
Tuma, Katja  
Scandariato, Riccardo  
TORE-URI
http://hdl.handle.net/11420/10262
First published in
Lecture notes in computer science  
Number in series
11048 LNCS
Start Page
347
End Page
363
Citation
European Conference on Software Architecture (ECSA 2018)
Contribution to Conference
12th European Conference on Software Architecture, ECSA 2018  
Publisher DOI
10.1007/978-3-030-00761-4_23
Scopus ID
2-s2.0-85057224414
In an initial attempt to systematize the research field of architectural threat analysis, this paper presents a comparative study of two threat analysis techniques. In particular, the controlled experiment presented here compares two variants of Microsoft’s STRIDE. The two variants differ in the way the analysis is performed. In one case, each component of the software system is considered in isolation and scrutinized for potential security threats. In the other case, the analysis has a wider scope and considers the security threats that might occur in a pair of interacting software components. The study compares the techniques with respect to their effectiveness in finding security threats (benefits) as well as the time that it takes to perform the analysis (cost). We also look into other human aspects which are important for industrial adoption, like, for instance, the perceived difficulty in learning and applying the techniques as well as the overall preference of our experimental participants.
Subjects
Empirical study
Secure software
STRIDE
Threat analysis
TUHH
Weiterführende Links
  • Contact
  • Send Feedback
  • Cookie settings
  • Privacy policy
  • Impress
DSpace Software

Built with DSpace-CRIS software - Extension maintained and optimized by 4Science
Design by effective webwork GmbH

  • Deutsche NationalbibliothekDeutsche Nationalbibliothek
  • ORCiD Member OrganizationORCiD Member Organization
  • DataCiteDataCite
  • Re3DataRe3Data
  • OpenDOAROpenDOAR
  • OpenAireOpenAire
  • BASE Bielefeld Academic Search EngineBASE Bielefeld Academic Search Engine
Feedback