loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
11th IEEE International Software Metrics Symposium (METRICS'05)
Measurement Framework for Software Privilege Protection Based on User Interaction Analysis
Como, Italy
September 19-September 22
ISBN: 0-7695-2371-4
Michael Yanguo Liu, University of Victoria
Issa Traore, University of Victoria
Software security is a complex notion that has to be analyzed from several perspectives. One such perspective is the restriction and protection of software privileges. In other words, a secure software system should be able to prevent misuse of the privileges granted. Privileges are usually protected in software systems by integrating or implementing appropriate security modules or mechanisms. Knowing how system privileges are protected by security mechanisms helps software developers in reducing the security risks underlying software systems. In this paper, we propose a measurement framework to evaluate quantitatively the privilege protections of a software system at the design level. Our analysis is based on modelling and analyzing user interactions based on the so-called User System Interaction Effect (USIE) Model. Specifically we define some measurement abstractions and associated metrics for assessing software privilege protection. We evaluate our framework by conducting an empirical study based on a medical record keeping software system.
Citation:
Michael Yanguo Liu, Issa Traore, "Measurement Framework for Software Privilege Protection Based on User Interaction Analysis," metrics, pp.10, 11th IEEE International Software Metrics Symposium (METRICS'05), 2005
Usage of this product signifies your acceptance of the Terms of Use.