Quantitative Risk Assessment Method Development in the Context of the SDLC-model


연구 분야: Infrastructure



학회: 2021 IEEE 8th International Conference on Problems of Infocommunications, Science and Technology (PIC S&T)


초록

The quantitative software development risk assessment method, which was developed to solve the problem of contradictions arising in the software development, if software developers neglect the factors of software security vulnerabilities, is examined in this work. A distinctive feature of the examined method is the integrated use of the “Fault tree analysis” technique and the method of estimating the net present value of the software development project with taking into account the negative factors of the possibility of not revealing software security vulnerabilities. The use of the improved “Fault tree analysis” technique will allow to increase the accuracy of quantitative risk assessment of software development by up to 22%. At the same time, the use of the method of estimating the net present value of the software development project allows the project to be considered in a comprehensive manner, taking into account the need for security accounting and software vulnerability testing using tools.


Author Profile
Oleksandr Kovalenko

Cybersecurity & Software Academic Department Central Ukrainian National Technical University Kropyvnytskyi Ukraine

Ukraine
Author Profile
Oleksii Smirnov

Cybersecurity & Software Academic Department Central Ukrainian National Technical University Kropyvnytskyi Ukraine

Ukraine
Author Profile
Anna Kovalenko

Cybersecurity & Software Academic Department Central Ukrainian National Technical University Kropyvnytskyi Ukraine

Ukraine

📄 논문 정보

발행 연도 2021년
인용수 2
출판 국가 Andorra, Ukraine
사이트 IEEE
좋아요 수 0

연관 논문 목록 (58건)