Back to Search Start Over

Identifying Implicit Vulnerabilities through Personas as Goal Models

Authors :
Claudia Iacob
Raian Ali
Duncan Ki-Aries
Shamal Faily
Source :
4th International Workshop on SECurity and Privacy Requirements Engineering (SECPRE 2020), Computer Security ISBN: 9783030643294, CyberICPS/SECPRE/ADIoT@ESORICS
Publication Year :
2020
Publisher :
Springer, 2020.

Abstract

When used in requirements processes and tools, personas have the potential to identify vulnerabilities resulting from misalignment between user expectations and system goals. Typically, however, this potential is unfulfilled as personas and system goals are captured with different mindsets, by different teams, and for different purposes. If personas are visualised as goal models, it may be easier for stakeholders to see implications of their goals being satisfied or denied, and designers to incorporate the creation and analysis of such models into the broader RE tool-chain. This paper outlines a tool-supported approach for finding implicit vulnerabilities from user and system goals by reframing personas as social goal models. We illustrate this approach with a case study where previously hidden vulnerabilities based on human behaviour were identified.<br />SECPRE 2020 workshop pre-print

Details

Language :
English
ISBN :
978-3-030-64329-4
ISBNs :
9783030643294
Database :
OpenAIRE
Journal :
4th International Workshop on SECurity and Privacy Requirements Engineering (SECPRE 2020), Computer Security ISBN: 9783030643294, CyberICPS/SECPRE/ADIoT@ESORICS
Accession number :
edsair.doi.dedup.....806e49d999d3571f258846db971b02ea