错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Method Based on Behavior Driven Development (BDD) and System-Theoretic Process Analysis (STPA) for Verifying Security Requirements in Critical Software Systems

  • Vitor Rubatino,
  • Alice Batista Nogueira,
  • Fellipe Guilherme Rey de Souza,
  • Rodrigo Martins Pagliares

摘要

Security failures in critical software systems can lead to severe economic, environmental, and human consequences. To ensure the security of these systems, it is necessary to identify and document security requirements as part of the software development process. Although the System-Theoretic Process Analysis (STPA) technique can be used to identify security requirements, it is challenging to verify their accuracy, completeness, and consistency. We propose a method based on STPA and Behavior Driven Development (BDD) for verifying software security requirements. BDD establishes a common language between business analysts and software developers. We evaluate the method through examples related to preserving the Confidentiality, Integrity, and Availability (CIA) of information. The application of the method to the examples produces automated test cases written using Gherkin syntax, which are used to verify the requirements in the examples. The method proposed in this work has the potential to generate automated test cases that can be used to verify whether the software solution built meets the security requirements identified through an STPA analysis.