Skip to main content

Metrics of Software Security

  • Reference work entry
Encyclopedia of Cryptography and Security

Synonyms

Measurement models of software security

Related Concepts

Fault Trees; Patterns for Software Security

Definition

Measuring software security requires to identify measurable properties of a software artifact and to build models that can relate the measures to a qualitative or quantitative value of the property “security.”

Background

Security measurement of software products is an instance of the more general issue of measuring nonfunctional properties of software (the so-called software qualities).

This includes both the need to identify measurable properties of a software artifact and to build models that can relate the measures to a qualitative or quantitative evaluation of the more abstract property “security.”

This requires, in general, a variety of measures to be integrated (through models) into the more abstract property “security.” The reason is that different aspects concerning different development phases (for instance design and programming) may affect the software...

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Chapter
USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD 799.99
Price excludes VAT (USA)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever
Hardcover Book
USD 949.99
Price excludes VAT (USA)
  • Durable hardcover edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

Recommended Reading

  1. Nichols EA, Peterson G (2007) A metrics framework to drive application security improvement. IEEE Secur Priv 5(2): 88–91

    Google Scholar 

  2. Heyman T, Scandariato R, Huygens C, Joosen W (2008) Using security patterns to combine security metrics. In: Proceedings of the third international conference on availability, security and reliability, ARES, Barcelona, Spain. IEEE Computer Society, pp 1156–1163

    Google Scholar 

  3. Barnum S, McGraw G (2005) Knowledge for software security. IEEE Secur Priv 3(2):74–78

    Google Scholar 

  4. Owasp Top 10. http://www.owasp.org/index.php/Top_10_2007

  5. Hoglund G, McGraw G (2004) Exploiting software: how to break code. Addison Wesley, Boston

    Google Scholar 

  6. Andrews M, Whittacker JA (2006) How to break web software. Addison-Wesley, Upper Saddle River

    Google Scholar 

  7. Schneier B (1999) Attack trees: modeling security threats. Dr. Dobb’s J Softw Tools 24(12):21–29

    Google Scholar 

  8. Piazzalunga U, Salvaneschi P, Balducci F, Jacomuzzi P, Moroncelli C (2007) Security strength measurement for dongle protected software. IEEE Secur Priv 5(6):32–40

    Google Scholar 

  9. Sahinoglu M (2005) Security meter: a practical decision-tree model to quantify risk. IEEE Secur Priv 3(3):18–24

    Google Scholar 

  10. Grunske L, Joyce D (2008) Quantitative risk-based security prediction for component-based systems with explicitly modeled attack profiles. J Syst Softw 81(8):1327–1345

    Google Scholar 

  11. Nicol DM, Sanders WH, Trivedi KS (2004) Model-based evaluation: from dependability to security. IEEE Trans Dependable Secure Comput 1(1):48–65

    Google Scholar 

  12. Halkidis ST, Tsantalis N, Chatzigeorgiou A, Stephanides G (2008) Architectural risk analysis of software systems based on security patterns. IEEE Trans Dependable Secure Comput 5(3):129–142

    Google Scholar 

  13. Sharma VS, Trivedi KS (2005) Architecture based analysis of performance, reliability and security of software systems. In: Proceedings of the 5th international workshop on software and performance, Palma, Iles Balears, Spain. ACM Press, pp 17–227

    Google Scholar 

Download references

Author information

Authors and Affiliations

Authors

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2011 Springer Science+Business Media, LLC

About this entry

Cite this entry

Salvaneschi, G., Salvaneschi, P. (2011). Metrics of Software Security. In: van Tilborg, H.C.A., Jajodia, S. (eds) Encyclopedia of Cryptography and Security. Springer, Boston, MA. https://doi.org/10.1007/978-1-4419-5906-5_680

Download citation

Publish with us

Policies and ethics