Environment-driven Threats Elicitation for Web Applications

Hui Guan,Weiru Chen,Lin Liu,Hongji Yang
DOI: https://doi.org/10.1007/978-3-642-22000-5_31
2011-01-01
Abstract:The popularity and complexity of web application present challenges to the security implementation for web engineering. Threat elicitation is an indispensable step for developers to identify the possible threats to the web applications in the early phase of software development. In this context, a novel approach is proposed to ease the threats elicitation for web application by using a defined web application classification as the sieve to sift a common threat list. The final result shows that the proposed model is a simplified and effective solution to threats elicitation to web application.
What problem does this paper attempt to address?