Projects of affiliated persons per year
Abstract
Models of software systems are used throughout the software development lifecycle. Dataflow diagrams (DFDs), in particular, are well-established resources for security analysis. Many techniques, such as threat modelling, are based on DFDs of the analysed application. However, their impact on the performance of analysts in a security analysis setting has not been explored before. In this paper, we present the findings of an empirical experiment conducted to investigate this effect. Following a within-groups design, participants were asked to solve security-relevant tasks for a given microservice application. In the control condition, the participants had to examine the source code manually. In the model-supported condition, they were additionally provided a DFD of the analysed application and traceability information linking model items to artefacts in source code. We found that the participants (n = 24) performed significantly better in answering the analysis tasks correctly in the model-supported condition (41 % increase in analysis correctness). Further, participants who reported using the provided traceability information performed better in giving evidence for their answers (315% increase in correctness of evidence). Finally, we identified three open challenges of using DFDs for security analysis based on the insights gained in the experiment.
| Original language | English |
|---|---|
| Title of host publication | IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER) |
| Subtitle of host publication | Proceedings |
| Publisher | IEEE |
| Pages | 952-963 |
| Number of pages | 12 |
| ISBN (Electronic) | 9798350330663 |
| DOIs | |
| Publication status | Published - 2024 |
| Event | IEEE International Conference on Software Analysis, Evolution and Reengineering - Rovaniemi, Finland Duration: 12 Mar 2024 → 15 Mar 2024 https://conf.researchr.org/home/saner-2024 |
Conference
| Conference | IEEE International Conference on Software Analysis, Evolution and Reengineering |
|---|---|
| Abbreviated title | SANER 2024 |
| Country/Territory | Finland |
| City | Rovaniemi |
| Period | 12/03/24 → 15/03/24 |
| Internet address |
Austrian Fields of Science 2012
- 102022 Software development
Keywords
- security
- empirical experiment
- model-based
- dataflow diagrams
- analysis
- microservices
Fingerprint
Dive into the research topics of 'How Dataflow Diagrams Impact Software Security Analysis: an Empirical Experiment'. Together they form a unique fingerprint.Projects
- 1 Finished
-
AssureMOSS: Assurance and certification in secure Multi-party Open Software and Services
Zdun, U. (Project Lead), Simhandl, G. (Scientific Project Staff), Quéval, P.-J. (Scientific Project Staff) & Ennsberger, S. (Admin)
1/10/20 → 30/09/23
Project: Research funding
Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver