Saved in:
Bibliographic Details
Main Authors: Mbaka, Winnie Bahati, Tuma, Katja
Format: Preprint
Published: 2024
Subjects:
Online Access:https://arxiv.org/abs/2408.07537
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914913254899712
author Mbaka, Winnie Bahati
Tuma, Katja
author_facet Mbaka, Winnie Bahati
Tuma, Katja
contents The arrival of recent cybersecurity standards has raised the bar for security assessments in organizations, but existing techniques don't always scale well. Threat analysis and risk assessment are used to identify security threats for new or refactored systems. Still, there is a lack of definition-of-done, so identified threats have to be validated which slows down the analysis. Existing literature has focused on the overall performance of threat analysis, but no previous work has investigated how deep must the analysts dig into the material before they can effectively validate the identified security threats. We propose a controlled experiment with practitioners to investigate whether some analysis material (like LLM-generated advice) is better than none and whether more material (the system's data flow diagram and LLM-generated advice) is better than some material. In addition, we present key findings from running a pilot with 41 MSc students, which are used to improve the study design. Finally, we also provide an initial replication package, including experimental material and data analysis scripts and a plan to extend it to include new materials based on the final data collection campaign with practitioners (e.g., pre-screening questions).
format Preprint
id arxiv_https___arxiv_org_abs_2408_07537
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Usefulness of data flow diagrams and large language models for security threat validation: a registered report
Mbaka, Winnie Bahati
Tuma, Katja
Software Engineering
The arrival of recent cybersecurity standards has raised the bar for security assessments in organizations, but existing techniques don't always scale well. Threat analysis and risk assessment are used to identify security threats for new or refactored systems. Still, there is a lack of definition-of-done, so identified threats have to be validated which slows down the analysis. Existing literature has focused on the overall performance of threat analysis, but no previous work has investigated how deep must the analysts dig into the material before they can effectively validate the identified security threats. We propose a controlled experiment with practitioners to investigate whether some analysis material (like LLM-generated advice) is better than none and whether more material (the system's data flow diagram and LLM-generated advice) is better than some material. In addition, we present key findings from running a pilot with 41 MSc students, which are used to improve the study design. Finally, we also provide an initial replication package, including experimental material and data analysis scripts and a plan to extend it to include new materials based on the final data collection campaign with practitioners (e.g., pre-screening questions).
title Usefulness of data flow diagrams and large language models for security threat validation: a registered report
topic Software Engineering
url https://arxiv.org/abs/2408.07537