
<ns0:uwmetadata xmlns:ns0="http://phaidra.univie.ac.at/XML/metadata/V1.0" xmlns:ns1="http://phaidra.univie.ac.at/XML/metadata/lom/V1.0" xmlns:ns10="http://phaidra.univie.ac.at/XML/metadata/provenience/V1.0" xmlns:ns11="http://phaidra.univie.ac.at/XML/metadata/provenience/V1.0/entity" xmlns:ns12="http://phaidra.univie.ac.at/XML/metadata/digitalbook/V1.0" xmlns:ns13="http://phaidra.univie.ac.at/XML/metadata/etheses/V1.0" xmlns:ns2="http://phaidra.univie.ac.at/XML/metadata/extended/V1.0" xmlns:ns3="http://phaidra.univie.ac.at/XML/metadata/lom/V1.0/entity" xmlns:ns4="http://phaidra.univie.ac.at/XML/metadata/lom/V1.0/requirement" xmlns:ns5="http://phaidra.univie.ac.at/XML/metadata/lom/V1.0/educational" xmlns:ns6="http://phaidra.univie.ac.at/XML/metadata/lom/V1.0/annotation" xmlns:ns7="http://phaidra.univie.ac.at/XML/metadata/lom/V1.0/classification" xmlns:ns8="http://phaidra.univie.ac.at/XML/metadata/lom/V1.0/organization" xmlns:ns9="http://phaidra.univie.ac.at/XML/metadata/histkult/V1.0">
  <ns1:general>
    <ns1:identifier>o:32584</ns1:identifier>
    <ns1:title language="en">Software Security Analysis, Metrics, and Test Design Considerations</ns1:title>
    <ns1:language>en</ns1:language>
    <ns1:description language="en">Abstract: Software security addresses the degree to which software can be exploited or misused. Software
development is not yet a science or a rigorous discipline, and the development process by and large is not
controlled to minimize the vulnerabilities that attackers exploit. Security is a blend of -enhanced processes and
practices—and the skilled people to perform them— which are required to build software that can be trusted
not to increase risk exposure. Three categories of analysis provide such a blend: threat modeling, risk analysis,
and security assessment and testing. This article discusses the role of software testing in a security-oriented
software development process. It focuses on two related topics: functional security testing and risk-based
security testing. Any endeavor worth pursuing is worth measuring, but software security presents new
measurement challenges: there are no established formulas or procedures for quantifying the security risk
present in a program. This paper details the importance of measuring software security and discusses the lessthan
satisfying approaches that are prevalent today. A new set of metrics is then proposed for ensuring an
accurate and comprehensive view of software projects ranging from legacy systems to newly deployed web
applications. Many of the new metrics make use of source code analysis results.</ns1:description>
    <ns1:keyword language="en">KeyWords: Security issues, security testing, security metrics, security risks</ns1:keyword>
    <ns2:identifiers>
      <ns2:resource>1552100</ns2:resource>
      <ns2:identifier>978-1-61804-126-5</ns2:identifier>
    </ns2:identifiers>
  </ns1:general>
  <ns1:lifecycle>
    <ns1:upload_date>2024-01-27T10:30:51.587Z</ns1:upload_date>
    <ns1:status>44</ns1:status>
    <ns2:peer_reviewed>no</ns2:peer_reviewed>
    <ns1:contribute seq="0">
      <ns1:role>46</ns1:role>
      <ns1:entity seq="0">
        <ns3:firstname>Ljubomir </ns3:firstname>
        <ns3:lastname>Lazić</ns3:lastname>
        <ns3:institution>Državni univerzitet u Novom Pazaru</ns3:institution>
        <ns3:orcid>0000-0001-9839-1238</ns3:orcid>
      </ns1:entity>
      <ns1:entity seq="1">
        <ns3:firstname>Dženan </ns3:firstname>
        <ns3:lastname>Avdić</ns3:lastname>
        <ns3:institution>Državni univerzitet u Novom Pazaru</ns3:institution>
        <ns3:type>person</ns3:type>
        <ns3:orcid>0000-0002-7729-3652</ns3:orcid>
      </ns1:entity>
      <ns1:entity seq="2">
        <ns3:firstname>Aldina </ns3:firstname>
        <ns3:lastname>Pljasković</ns3:lastname>
        <ns3:institution>Državni univerzitet u Novom Pazaru</ns3:institution>
        <ns3:type>person</ns3:type>
        <ns3:conor>29219175</ns3:conor>
        <ns3:orcid>0000-0003-4312-3839</ns3:orcid>
      </ns1:entity>
    </ns1:contribute>
  </ns1:lifecycle>
  <ns1:technical>
    <ns1:format>application/pdf</ns1:format>
    <ns1:size>778218</ns1:size>
    <ns1:location>https://phaidrabg.bg.ac.rs/o:32584</ns1:location>
  </ns1:technical>
  <ns1:rights>
    <ns1:cost>no</ns1:cost>
    <ns1:copyright>yes</ns1:copyright>
    <ns1:license>16</ns1:license>
  </ns1:rights>
  <ns1:classification>
    <ns1:purpose>70</ns1:purpose>
  </ns1:classification>
  <ns1:organization>
    <ns8:hoschtyp>92000001</ns8:hoschtyp>
    <ns8:orgassignment>
      <ns8:faculty>20A01</ns8:faculty>
    </ns8:orgassignment>
  </ns1:organization>
  <ns12:digitalbook>
    <ns12:name_magazine language="en">Proceedings of the 6th WSEAS European Computing Conference (ECC &apos;12) Prague</ns12:name_magazine>
    <ns12:from_page>355</ns12:from_page>
    <ns12:to_page>367</ns12:to_page>
    <ns12:releaseyear>2012</ns12:releaseyear>
  </ns12:digitalbook>
</ns0:uwmetadata>
