论文标题

威胁分析的人类方面:复制

Human Aspect of Threat Analysis: A Replication

论文作者

Tuma, Katja, Mbaka, Winnie

论文摘要

背景:组织正在经历对安全活动的安全需求(例如,大步分析),需要大量的手动努力。由于目前缺乏多种多样(且足够的)安全劳动力以及过去研究的确定结果,这种情况恶化了。迄今为止,在威胁分析中发挥作用的决定性因素(例如多样性维度)尚未得到充分探索。目的:为了解决这个问题,我们计划进行一系列探索性控制的实验。主要目的是从经验上衡量人类观察,这些人与更知名的分析绩效指标一起在威胁分析中发挥作用。方法:我们将实验设计为过去实验的分化复制。复制设计旨在捕获一些类似的措施(例如,结果质量)和其他措施(例如多样性维度)。我们计划在学术环境中进行实验。局限性:在高级计算机科学课程中获得平衡的人群(例如WRT性别)是不现实的。我们计划与MSC级别的学生进行的实验肯定会遭受这一限制。

Background: Organizations are experiencing an increasing demand for security-by-design activities (e.g., STRIDE analyses) which require a high manual effort. This situation is worsened by the current lack of diverse (and sufficient) security workforce and inconclusive results from past studies. To date, the deciding human factors (e.g., diversity dimensions) that play a role in threat analysis have not been sufficiently explored. Objective: To address this issue, we plan to conduct a series of exploratory controlled experiments. The main objective is to empirically measure the human-aspects that play a role in threat analysis alongside the more well-known measures of analysis performance. Method: We design the experiments as a differentiated replication of past experiments with STRIDE. The replication design is aimed at capturing some similar measures (e.g., of outcome quality) and additional measures (e.g., diversity dimensions). We plan to conduct the experiments in an academic setting. Limitations: Obtaining a balanced population (e.g., wrt gender) in advanced computer science courses is not realistic. The experiments we plan to conduct with MSc level students will certainly suffer this limitation.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源