Software Security Measurements: A Survey
Author
Abstract

Predictive Security Metrics - Security metrics for software products give a quantifiable assessment of a software system s trustworthiness. Metrics can also help detect vulnerabilities in systems, prioritize corrective actions, and raise the level of information security within the business. There is a lack of studies that identify measurements, metrics, and internal design properties used to assess software security. Therefore, this paper aims to survey security measurements used to assess and predict security vulnerabilities. We identified the internal design properties that were used to measure software security based on the internal structure of the software. We also identified the security metrics used in the studies we examined. We discussed how software refactoring had been used to improve software security. We observed that a software system with low coupling, low complexity, and high cohesion is more secure and vice versa. Current research directions have been identified and discussed.

Year of Publication
2022
Date Published
dec
Publisher
IEEE
Conference Location
Hadhramaut, Yemen
ISBN Number
978-1-66545-998-3
URL
https://ieeexplore.ieee.org/document/9990968/
DOI
10.1109/ITSS-IoE56359.2022.9990968
Google Scholar | BibTeX | DOI