Deakin University
Browse

Automated support to capture and validate security requirements for mobile apps

Version 2 2024-06-06, 12:01
Version 1 2017-02-27, 12:06
conference contribution
posted on 2024-06-06, 12:01 authored by N Yusop, M Kamalrudin, S Sidek, J Grundy
Mobile application usage has become widespread and significant as it allows interactions between people and services anywhere and anytime. However, issues related to security have become a major concern among mobile users as insecure applications may lead to security vulnerabilities that make them easily compromised by hackers. Thus, it is important for mobile application developers to validate security requirements of mobile apps at the earliest stage to prevent potential security problems. In this paper, we describe our automated approach and tool, called MobiMEReq that helps to capture and validate the security attributes requirements of mobile apps. We employed the concept of Test Driven Development (TDD) with a model-based testing strategy using Essential Use Cases (EUCs) and Essential User Interface (EUI) models. We also conducted an evaluation to compare the performance and correctness of our tool in various application domains. The results of the study showed that our tool is able to help requirements engineers to easily capture and validate security-related requirements of mobile applications.

History

Volume

671

Pagination

97-112

Location

Nagoya, Japan

Start date

2016-11-10

End date

2016-11-12

ISSN

1865-0929

ISBN-13

9789811032554

Language

eng

Publication classification

E1 Full written paper - refereed

Copyright notice

2016, Springer Nature

Editor/Contributor(s)

Lee SW, Nakatani T

Title of proceedings

APRES 2016 : Towards Sustainable World : Proceedings of the 3rd Asia-Pacific Requirements Engineering Symposium

Event

Asia Pacific Requirements Engineering. Symposium (3rd : 2016 : Nagoya, Japan)

Publisher

Springer

Place of publication

Singapore

Series

Communications in Computer and Information Science