

Security metrics for source code structures

15 years 2 months ago
Security metrics for source code structures
Software security metrics are measurements to assess security related imperfections (or perfections) introduced during software development. A number of security metrics have been proposed. However, all the perspectives of a software system have not been provided specific attention. While most security metrics evaluate software from a system-level perspective, it can also be useful to analyze defects at a lower level, i.e., at the source code level. To address this issue, we propose some code-level security metrics which can be used to suggest the level of security of a code segment. We provide guidelines about where and how these metrics can be used to improve source code structures. We have also conducted two case studies to demonstrate the applicability of the proposed metrics. Categories and Subject Descriptors D.2.8 [Software Engineering]: Metrics ? Performance measures and Product metrics. General Terms Measurements and Security. Keywords Metrics, security metrics, code quality ...
Istehad Chowdhury, Brian Chan, Mohammad Zulkernine
Added 09 Dec 2009
Updated 09 Dec 2009
Type Conference
Year 2008
Where ICSE
Authors Istehad Chowdhury, Brian Chan, Mohammad Zulkernine
Comments (0)