Facebook pixel tracking

The Science and Information (SAI) Organization publishes open-access peer-reviewed journals in computer science and artificial intelligence.

Contact Info
Website thesai.org
Follow Us
Contact Info
Follow Us
Research Article | Open Access |

Secure Software Engineering: A Knowledge Modeling based Approach for Inferring Association between Source Code and Design Artifacts

Author 1: Chaman Wijesiriwardana Author 2: Ashanthi Abeyratne Author 3: Chamal Samarage Author 4: Buddika Dahanayake Author 5: Prasad Wimalaratne
International Journal of Advanced Computer Science and Applications (IJACSA) · Vol. 11, No. 12 · Published 2020

DOI: https://doi.org/10.14569/IJACSA.2020.0111282

Abstract

Secure software engineering has emerged in recent decades by encouraging the idea of software security has to be an integral part of all the phases of the software development lifecycle. As a result, each phase of the lifecycle is associated with security-specific best practices such as threat modeling and static code analysis. It was observed that various artifacts (i.e., security requirements, architectural flaws, bug reports, security test cases) generated as a result of security best practices tend to be segregated. This creates a significant barrier to resolve the security issues at the implementation phase since most of them are originated in the design phase. In order to address this issue, this paper presents a knowledge-modeling based approach to semantically infer the associations between architectural level security flaws and code-level security bugs, which is manually tedious. Threat modeling and static analysis are used to identify security flaws and security bugs, respectively. The case study based experimental results revealed that the architectural level security flaws have a significant impact on originating security bugs in the code level. Besides, the evaluation results confirmed the scalability of the proposed approach to large-scale industrial software products.

Keywords

How to Cite this Article

Wijesiriwardana, C., Abeyratne, A., Samarage, C., Dahanayake, B., & Wimalaratne, P. (2020). Secure Software Engineering: A Knowledge Modeling based Approach for Inferring Association between Source Code and Design Artifacts. International Journal of Advanced Computer Science and Applications, 11(12). https://doi.org/10.14569/IJACSA.2020.0111282

Wijesiriwardana, Chaman, et al.. "Secure Software Engineering: A Knowledge Modeling based Approach for Inferring Association between Source Code and Design Artifacts." International Journal of Advanced Computer Science and Applications, vol. 11, no. 12, 2020, https://doi.org/10.14569/IJACSA.2020.0111282.

@article{Wijesiriwardana2020,
  title     = {Secure Software Engineering: A Knowledge Modeling based Approach for Inferring Association between Source Code and Design Artifacts},
  journal   = {International Journal of Advanced Computer Science and Applications},
  volume    = {11},
  number    = {12},
  year      = {2020},
  publisher = {The Science and Information Organization},
  author    = {Chaman Wijesiriwardana and Ashanthi Abeyratne and Chamal Samarage and Buddika Dahanayake and Prasad Wimalaratne},
  doi       = {10.14569/IJACSA.2020.0111282},
  url       = {https://doi.org/10.14569/IJACSA.2020.0111282}
}

Open Access — licensed under a Creative Commons Attribution 4.0 International License. Unrestricted use, distribution, and reproduction in any medium, even commercially, as long as the original work is properly cited.