
<oai_dc:dc xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:oai_dc="http://www.openarchives.org/OAI/2.0/oai_dc/">
  <dc:subject xml:lang="eng">KeyWords: Security issues, security testing, security metrics, security risks</dc:subject>
  <dc:rights>http://creativecommons.org/licenses/by/4.0/legalcode</dc:rights>
  <dc:creator id="https://orcid.org/0000-0001-9839-1238">Lazić, Ljubomir</dc:creator>
  <dc:creator id="https://orcid.org/0000-0002-7729-3652">Avdić, Dženan</dc:creator>
  <dc:creator id="https://orcid.org/0000-0003-4312-3839 https://plus.cobiss.net/cobiss/sr/sr/conor/29219175">Pljasković, Aldina</dc:creator>
  <dc:source>Proceedings of the 6th WSEAS European Computing Conference (ECC &apos;12) Prague</dc:source>
  <dc:description xml:lang="eng">Abstract: Software security addresses the degree to which software can be exploited or misused. Software
development is not yet a science or a rigorous discipline, and the development process by and large is not
controlled to minimize the vulnerabilities that attackers exploit. Security is a blend of -enhanced processes and
practices—and the skilled people to perform them— which are required to build software that can be trusted
not to increase risk exposure. Three categories of analysis provide such a blend: threat modeling, risk analysis,
and security assessment and testing. This article discusses the role of software testing in a security-oriented
software development process. It focuses on two related topics: functional security testing and risk-based
security testing. Any endeavor worth pursuing is worth measuring, but software security presents new
measurement challenges: there are no established formulas or procedures for quantifying the security risk
present in a program. This paper details the importance of measuring software security and discusses the lessthan
satisfying approaches that are prevalent today. A new set of metrics is then proposed for ensuring an
accurate and comprehensive view of software projects ranging from legacy systems to newly deployed web
applications. Many of the new metrics make use of source code analysis results.</dc:description>
  <dc:format>application/pdf</dc:format>
  <dc:format>778218 bytes</dc:format>
  <dc:language>eng</dc:language>
  <dc:identifier>https://phaidrabg.bg.ac.rs/o:32584</dc:identifier>
  <dc:title xml:lang="eng">Software Security Analysis, Metrics, and Test Design Considerations</dc:title>
  <dc:type>info:eu-repo/semantics/article</dc:type>
  <dc:date>2012</dc:date>
</oai_dc:dc>
