Automated support to capture and validate security requirements for mobile apps
Version 2 2024-06-06, 12:01Version 2 2024-06-06, 12:01
Version 1 2017-02-27, 12:06Version 1 2017-02-27, 12:06
conference contribution
posted on 2024-06-06, 12:01authored byN Yusop, M Kamalrudin, S Sidek, J Grundy
Mobile application usage has become widespread and significant as it allows interactions between people and services anywhere and anytime. However, issues related to security have become a major concern among mobile users as insecure applications may lead to security vulnerabilities that make them easily compromised by hackers. Thus, it is important for mobile application developers to validate security requirements of mobile apps at the earliest stage to prevent potential security problems. In this paper, we describe our automated approach and tool, called MobiMEReq that helps to capture and validate the security attributes requirements of mobile apps. We employed the concept of Test Driven Development (TDD) with a model-based testing strategy using Essential Use Cases (EUCs) and Essential User Interface (EUI) models. We also conducted an evaluation to compare the performance and correctness of our tool in various application domains. The results of the study showed that our tool is able to help requirements engineers to easily capture and validate security-related requirements of mobile applications.
History
Volume
671
Pagination
97-112
Location
Nagoya, Japan
Start date
2016-11-10
End date
2016-11-12
ISSN
1865-0929
ISBN-13
9789811032554
Language
eng
Publication classification
E1 Full written paper - refereed
Copyright notice
2016, Springer Nature
Editor/Contributor(s)
Lee SW, Nakatani T
Title of proceedings
APRES 2016 : Towards Sustainable World : Proceedings of the 3rd Asia-Pacific Requirements Engineering Symposium