Software Protection as a Risk Analysis Process

11/14/2020
by   Daniele Canavese, et al.
0

The last years have seen an increase of Man-at-the-End (MATE) attacks against software applications, both in number and severity. However, MATE software protections are dominated by fuzzy concepts and techniques, and security-through-obscurity is omnipresent in this field. In this paper, we present a rationale for adopting and standardizing the protection of software as a risk management process according to the NIST SP800-39 approach. We examine the relevant aspects of formalizing and automating the risk management activities, to instigate the necessary actions for adoption. We highlight the open issues that the research community has to address. We discuss the benefits that such an approach can bring to all stakeholders, from software developers to protections designers, and for the security of all the citizens. In addition, we present a Proof of Concept (PoC) of a decision support system that automates the risk analysis methodology towards the protection of software applications. Despite being in an embryonic stage, the PoC proved during validation with industry experts that several aspects of the risk management process can already be formalized and that it is an excellent starting point for building an industrial-grade decision support system.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
03/27/2023

Design, Implementation, and Automation of a Risk Management Approach for Man-at-the-End Software Protection

The last years have seen an increase in Man-at-the-End (MATE) attacks ag...
research
10/13/2022

Forensic-Ready Risk Management Concepts

Currently, numerous approaches exist supporting the implementation of fo...
research
04/05/2022

Factors Hindering the Adoption of DevOps in the Saudi Software Industry

DevOps has gained high importance in the global software industry due to...
research
03/04/2020

Risk Management Practices in Information Security: Exploring the Status Quo in the DACH Region

Information security management aims at ensuring proper protection of in...
research
07/28/2022

A Civil Protection Early Warning System to Improve the Resilience of Adriatic-Ionian Territories to Natural and Man-made Risk

We are currently witnessing an increased occurrence of extreme weather e...
research
06/14/2022

Data security as a top priority in the digital world: preserve data value by being proactive and thinking security first

Today, large amounts of data are being continuously produced, collected,...
research
01/15/2022

Chatbot Based Solution for Supporting Software Incident Management Process

A set of steps for implementing a chatbot, to support decision-making ac...

Please sign up or login with your details

Forgot password? Click here to reset