A Taxonomy of Functional Security Features and How They Can Be Located

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Hermann, Kevin, Schneider, Simon, Tony, Catherine, Yardim, Asli, Peldszus, Sven, Berger, Thorsten, Scandariato, Riccardo, Sasse, M. Angela, Naiakshina, Alena
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866908562397069312
author Hermann, Kevin
Schneider, Simon
Tony, Catherine
Yardim, Asli
Peldszus, Sven
Berger, Thorsten
Scandariato, Riccardo
Sasse, M. Angela
Naiakshina, Alena
author_facet Hermann, Kevin
Schneider, Simon
Tony, Catherine
Yardim, Asli
Peldszus, Sven
Berger, Thorsten
Scandariato, Riccardo
Sasse, M. Angela
Naiakshina, Alena
contents Security must be considered in almost every software system. Unfortunately, selecting and implementing security features remains challenging due to the variety of security threats and possible countermeasures. While security standards are intended to help developers, they are usually too abstract and vague to help implement security features, or they merely help configure such. A resource that describes security features at an abstraction level between high-level (i.e., rather too general) and low-level (i.e., rather too specific) security standards could facilitate secure systems development. To realize security features, developers typically use external security frameworks, to minimize implementation mistakes. Even then, developers still make mistakes, often resulting in security vulnerabilities. When security incidents occur or the system needs to be audited or maintained, it is essential to know the implemented security features and, more importantly, where they are located. This task, commonly referred to as feature location, is often tedious and error-prone. Therefore, we have to support long-term tracking of implemented security features. We present a study of security features in the literature and their coverage in popular security frameworks. We contribute (1) a taxonomy of 68 functional implementation-level security features including a mapping to widely used security standards, (2) an examination of 21 popular security frameworks concerning which of these security features they provide, and (3) a discussion on the representation of security features in source code. Our taxonomy aims to aid developers in selecting appropriate security features and frameworks and relating them to security standards when they need to choose and implement security features for a software system.
format Preprint
id arxiv_https___arxiv_org_abs_2501_04454
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle A Taxonomy of Functional Security Features and How They Can Be Located
Hermann, Kevin
Schneider, Simon
Tony, Catherine
Yardim, Asli
Peldszus, Sven
Berger, Thorsten
Scandariato, Riccardo
Sasse, M. Angela
Naiakshina, Alena
Cryptography and Security
Software Engineering
Security must be considered in almost every software system. Unfortunately, selecting and implementing security features remains challenging due to the variety of security threats and possible countermeasures. While security standards are intended to help developers, they are usually too abstract and vague to help implement security features, or they merely help configure such. A resource that describes security features at an abstraction level between high-level (i.e., rather too general) and low-level (i.e., rather too specific) security standards could facilitate secure systems development. To realize security features, developers typically use external security frameworks, to minimize implementation mistakes. Even then, developers still make mistakes, often resulting in security vulnerabilities. When security incidents occur or the system needs to be audited or maintained, it is essential to know the implemented security features and, more importantly, where they are located. This task, commonly referred to as feature location, is often tedious and error-prone. Therefore, we have to support long-term tracking of implemented security features. We present a study of security features in the literature and their coverage in popular security frameworks. We contribute (1) a taxonomy of 68 functional implementation-level security features including a mapping to widely used security standards, (2) an examination of 21 popular security frameworks concerning which of these security features they provide, and (3) a discussion on the representation of security features in source code. Our taxonomy aims to aid developers in selecting appropriate security features and frameworks and relating them to security standards when they need to choose and implement security features for a software system.
title A Taxonomy of Functional Security Features and How They Can Be Located
topic Cryptography and Security
Software Engineering
url https://arxiv.org/abs/2501.04454