Back to results

IUPUI

Analyzing and evaluating security features in software requirements

Abstract

dc:description.abstract

Software requirements, for complex projects, often contain specifications of non-functional attributes (e.g., security-related features). The process of analyzing such requirements for standards compliance is laborious and error prone. Due to the inherent free-flowing nature of software requirements, it is tempting to apply Natural Language Processing (NLP) and Machine Learning (ML) based techniques for analyzing these documents. In this thesis, we propose a novel semi-automatic methodology that assesses the security requirements of the software system with respect to completeness and ambiguity, creating a bridge between the requirements documents and being in compliance. Security standards, e.g., those introduced by the ISO and OWASP, are compared against annotated software project documents for textual entailment relationships (NLP), and the results are used to train a neural network model (ML) for classifying security-based requirements. Hence, this approach aims to identify the appropriate structures that underlie software requirements documents. Once such structures are formalized and empirically validated, they will provide guidelines to software organizations for generating comprehensive and unambiguous requirements specification documents as related to security-oriented features. The proposed solution will assist organizations during the early phases of developing secure software and reduce overall development effort and costs.

Degree

thesis:*
Discipline thesis:degree_discipline
Computer & Information Science
Year dc:date.issued
2016

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Hayrapetian, Allenoush
Advisor dc:contributor.advisor
  • Raje, Rajeev

Subjects

dc:subject × 6

Rights

dc:rights
Statement dc:rights
  • Attribution 3.0 United States
Language dc:language.iso
en_US

Identifiers

dc:identifier.*
OAI identifier oai:identifier
oai:scholarworks.indianapolis.iu.edu:1805/11837

Chain of custody

source
Harvested from
IUPUI
Base URL
scholarworks.indianapolis.iu.edu/server/oai/request
Last updated
2026-07-24
Source record
OAI-PMH GetRecord
citation

Hayrapetian, Allenoush. Analyzing and evaluating security features in software requirements. 2016. https://hdl.handle.net/1805/11837