Back to Search
Start Over
Identifying Implicit Vulnerabilities through Personas as Goal Models
- Source :
- 4th International Workshop on SECurity and Privacy Requirements Engineering (SECPRE 2020), Computer Security ISBN: 9783030643294, CyberICPS/SECPRE/ADIoT@ESORICS
- Publication Year :
- 2020
- Publisher :
- Springer, 2020.
-
Abstract
- When used in requirements processes and tools, personas have the potential to identify vulnerabilities resulting from misalignment between user expectations and system goals. Typically, however, this potential is unfulfilled as personas and system goals are captured with different mindsets, by different teams, and for different purposes. If personas are visualised as goal models, it may be easier for stakeholders to see implications of their goals being satisfied or denied, and designers to incorporate the creation and analysis of such models into the broader RE tool-chain. This paper outlines a tool-supported approach for finding implicit vulnerabilities from user and system goals by reframing personas as social goal models. We illustrate this approach with a case study where previously hidden vulnerabilities based on human behaviour were identified.<br />SECPRE 2020 workshop pre-print
- Subjects :
- FOS: Computer and information sciences
Computer Science - Cryptography and Security
Computer science
Computer Science - Human-Computer Interaction
020207 software engineering
02 engineering and technology
Cognitive reframing
Persona
User expectations
Data science
Human-Computer Interaction (cs.HC)
Software Engineering (cs.SE)
Computer Science - Software Engineering
0202 electrical engineering, electronic engineering, information engineering
020201 artificial intelligence & image processing
Cryptography and Security (cs.CR)
Subjects
Details
- Language :
- English
- ISBN :
- 978-3-030-64329-4
- ISBNs :
- 9783030643294
- Database :
- OpenAIRE
- Journal :
- 4th International Workshop on SECurity and Privacy Requirements Engineering (SECPRE 2020), Computer Security ISBN: 9783030643294, CyberICPS/SECPRE/ADIoT@ESORICS
- Accession number :
- edsair.doi.dedup.....806e49d999d3571f258846db971b02ea