RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기
    KCI등재

    Meeting Real Challenges in Eliciting Security Attributes for Mobile Application Development = Meeting Real Challenges in Eliciting Security Attributes for Mobile Application Development

    한글로보기

    https://www.riss.kr/link?id=A103035050

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수

    부가정보

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    There has been a rapid growth in the development of mobile application resulting from its wide usage for online transaction, data storage and exchange of information. However, an important issue that has been overlooked is the lack of emphasis on the security issues at the early stage of the development. In fact, security issues have been kept until the later stage of the implementation of mobile apps. Requirements engineers frequently ignore and incorrectly elicit security-related requirements at the early stage of mobile application development. This scenario has led to the failure of developing secure and safe mobile application based on the needs of the users. As such, this paper intends to provide further understanding of the real challenges in extracting security attributes for mobile application faced by novice requirements engineers. For this purpose, two experiments on eliciting security attributes requirements of textual requirements scenario were conducted. The performance related to the correctness and time taken to elicit the security attributes were measured and recorded. It was found that the process of eliciting correct security attributes for mobile application requires effort, knowledge and skills. The findings indicate that an automated tool for correct elicitation security attributes requirement could help to overcome the challenges in eliciting security attributes requirements, especially among novice requirements engineers.
    번역하기

    There has been a rapid growth in the development of mobile application resulting from its wide usage for online transaction, data storage and exchange of information. However, an important issue that has been overlooked is the lack of emphasis on the ...

    There has been a rapid growth in the development of mobile application resulting from its wide usage for online transaction, data storage and exchange of information. However, an important issue that has been overlooked is the lack of emphasis on the security issues at the early stage of the development. In fact, security issues have been kept until the later stage of the implementation of mobile apps. Requirements engineers frequently ignore and incorrectly elicit security-related requirements at the early stage of mobile application development. This scenario has led to the failure of developing secure and safe mobile application based on the needs of the users. As such, this paper intends to provide further understanding of the real challenges in extracting security attributes for mobile application faced by novice requirements engineers. For this purpose, two experiments on eliciting security attributes requirements of textual requirements scenario were conducted. The performance related to the correctness and time taken to elicit the security attributes were measured and recorded. It was found that the process of eliciting correct security attributes for mobile application requires effort, knowledge and skills. The findings indicate that an automated tool for correct elicitation security attributes requirement could help to overcome the challenges in eliciting security attributes requirements, especially among novice requirements engineers.

    더보기

    참고문헌 (Reference)

    1 M.S.Ware, "Using the Common Criteria to Elicit Security Requirements with Use Cases" 273-278, 2005

    2 C.L. Chen, "Using a Stored-Value Card to Provide an Added-Value Service of Payment Protocol in VANET" 660-665, 2013

    3 "User Authentication in Mobile Access"

    4 S. Yahya, "The Use of Essential Use Cases(EUCs)to enhance the Process of Capturing Security Requirements for Accurate Secure Software" 21-26, 2015

    5 N.Yusop, "Security Requirements Validation for Mobile Apps: A Systematic Literature Review" 2015

    6 C. B. Haley, "Security Requirements Engineering : A Framework for Representation and Analysis" 133-153, 2008

    7 E. Paja, "STS-tool : Socio-technical Security Requirements through social commitments" 331-332, 2012

    8 N. Nan, "Extractive Product Line Requirement"

    9 B.J.Berger, "Extracting and Analyzing the Implemented Security Architecture of Business Applications" 2013

    10 G.Ian, "Essential software architecture"

    1 M.S.Ware, "Using the Common Criteria to Elicit Security Requirements with Use Cases" 273-278, 2005

    2 C.L. Chen, "Using a Stored-Value Card to Provide an Added-Value Service of Payment Protocol in VANET" 660-665, 2013

    3 "User Authentication in Mobile Access"

    4 S. Yahya, "The Use of Essential Use Cases(EUCs)to enhance the Process of Capturing Security Requirements for Accurate Secure Software" 21-26, 2015

    5 N.Yusop, "Security Requirements Validation for Mobile Apps: A Systematic Literature Review" 2015

    6 C. B. Haley, "Security Requirements Engineering : A Framework for Representation and Analysis" 133-153, 2008

    7 E. Paja, "STS-tool : Socio-technical Security Requirements through social commitments" 331-332, 2012

    8 N. Nan, "Extractive Product Line Requirement"

    9 B.J.Berger, "Extracting and Analyzing the Implemented Security Architecture of Business Applications" 2013

    10 G.Ian, "Essential software architecture"

    11 P. Aho, "Enhancing generated Java GUI models with valid test data" 310-315, 2011

    12 S.Yahya, "Capturing Security Requirements Using Essential Use Cases (EUCs)" 16-30, 2014

    13 P. Vilhan, "Building Public Key Infrastructure for MANET with Help of B. A. T. M. A. N. Advanced" 566-571, 2013

    14 A. Kull, "Automatic GUI Model Generation: State of the Art" 207-212, 2012

    15 N. Ranjbar, "Authentication and Authorization for Mobile Devices"

    16 C. E.Loftis, "Attribute-level encryption of data in public Android databases" RTI Press

    17 I. Kashmala, "Analytical Survey for Assuring and Maintaining Quality of Mobile Applications"

    18 K.Ivo, "A comprehensive exploration of challenges in architecturebased reliability estimation" 202-227 : 2009

    19 A. Rekha, "A Survey on Encryption Algorithms for Data Security" 131-134, 2017

    20 S. Yahya, "A Review on Tool Supports for Security Requirements Engineering" 2013

    더보기

    동일학술지(권/호) 다른 논문

    동일학술지 더보기

    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    인용정보 인용지수 설명보기

    학술지 이력

    학술지 이력
    연월일 이력구분 이력상세 등재구분
    2027 평가 재인증평가 신청대상 (재인증)
    2021-01-01 등재 등재학술지 유지 (재인증) KCI등재
    2018-01-01 등재 등재학술지 유지 (등재유지) KCI등재
    2015-01-01 등재 등재학술지 유지 (등재유지) KCI등재
    2013-11-05 학술지명변경 외국어명 : Journal of Korean Society for Internet Information -> Journal of Internet Computing and Services KCI등재
    2011-01-01 등재 등재학술지 유지 (등재유지) KCI등재
    2009-01-01 등재 등재학술지 유지 (등재유지) KCI등재
    2006-01-01 등재 등재학술지 선정 (등재후보2차) KCI등재
    2005-01-01 등재 등재후보 1차 PASS (등재후보1차) KCI등재후보
    2003-01-01 등재 등재후보학술지 선정 (신규평가) KCI등재후보
    더보기

    학술지 인용정보

    학술지 인용정보
    기준연도 WOS-KCI 통합IF(2년) KCIF(2년) KCIF(3년)
    2016 0.55 0.55 0.63
    KCIF(4년) KCIF(5년) 중심성지수(3년) 즉시성지수
    0.64 0.6 0.85 0.03
    더보기

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼