Towards Analysis of Threat Modeling of Software Systems According to Key Criteria
摘要
Ensuring a high degree of software product security (cybersecurity) is one of the leading factors for its successful market realization. Therefore, various techniques and methodologies are integrated to ensure software security in the software development life cycle. This includes applying diverse approaches and methodologies for preventing threats and attacks on software. Various methodologies, such as modeling potential threats and attacks on software security, are often used to deal with these challenges. Threat modeling and future identification of potential threats and attacks on software are used. The paper focuses on the analysis of threat modeling methodologies and selected threat models used in the modeling threats process within the different stages of the software development life cycle. Based on the research, the paper presents specially selected four primary criteria, according to which the various methodologies for modeling threats are analyzed and documented. Among the main goals of the criteria is to support specialists from different fields in choosing the most appropriate methodology for modeling threats in the different stages of software development, as well as after the creation of the software.