Incorporating Verification Standards for Security Requirements Generation from Functional Specifications

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Lian, Xiaoli, Wang, Shuaisong, Zou, Hanyu, Liu, Fang, Wu, Jiajun, Zhang, Li
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866916741993463808
author Lian, Xiaoli
Wang, Shuaisong
Zou, Hanyu
Liu, Fang
Wu, Jiajun
Zhang, Li
author_facet Lian, Xiaoli
Wang, Shuaisong
Zou, Hanyu
Liu, Fang
Wu, Jiajun
Zhang, Li
contents In the current software driven era, ensuring privacy and security is critical. Despite this, the specification of security requirements for software is still largely a manual and labor intensive process. Engineers are tasked with analyzing potential security threats based on functional requirements (FRs), a procedure prone to omissions and errors due to the expertise gap between cybersecurity experts and software engineers. To bridge this gap, we introduce F2SRD (Function to Security Requirements Derivation), an automated approach that proactively derives security requirements (SRs) from functional specifications under the guidance of relevant security verification requirements (VRs) drawn from the well recognized OWASP Application Security Verification Standard (ASVS). F2SRD operates in two main phases: Initially, we develop a VR retriever trained on a custom database of FR and VR pairs, enabling it to adeptly select applicable VRs from ASVS. This targeted retrieval informs the precise and actionable formulation of SRs. Subsequently, these VRs are used to construct structured prompts that direct GPT4 in generating SRs. Our comparative analysis against two established models demonstrates F2SRD's enhanced performance in producing SRs that excel in inspiration, diversity, and specificity essential attributes for effective security requirement generation. By leveraging security verification standards, we believe that the generated SRs are not only more focused but also resonate stronger with the needs of engineers.
format Preprint
id arxiv_https___arxiv_org_abs_2505_11857
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Incorporating Verification Standards for Security Requirements Generation from Functional Specifications
Lian, Xiaoli
Wang, Shuaisong
Zou, Hanyu
Liu, Fang
Wu, Jiajun
Zhang, Li
Software Engineering
In the current software driven era, ensuring privacy and security is critical. Despite this, the specification of security requirements for software is still largely a manual and labor intensive process. Engineers are tasked with analyzing potential security threats based on functional requirements (FRs), a procedure prone to omissions and errors due to the expertise gap between cybersecurity experts and software engineers. To bridge this gap, we introduce F2SRD (Function to Security Requirements Derivation), an automated approach that proactively derives security requirements (SRs) from functional specifications under the guidance of relevant security verification requirements (VRs) drawn from the well recognized OWASP Application Security Verification Standard (ASVS). F2SRD operates in two main phases: Initially, we develop a VR retriever trained on a custom database of FR and VR pairs, enabling it to adeptly select applicable VRs from ASVS. This targeted retrieval informs the precise and actionable formulation of SRs. Subsequently, these VRs are used to construct structured prompts that direct GPT4 in generating SRs. Our comparative analysis against two established models demonstrates F2SRD's enhanced performance in producing SRs that excel in inspiration, diversity, and specificity essential attributes for effective security requirement generation. By leveraging security verification standards, we believe that the generated SRs are not only more focused but also resonate stronger with the needs of engineers.
title Incorporating Verification Standards for Security Requirements Generation from Functional Specifications
topic Software Engineering
url https://arxiv.org/abs/2505.11857