Volume 11 Number 5 (May 2016)
Home > Archive > 2016 > Volume 11 Number 5 (May 2016) >
JSW 2016 Vol.11(5): 520-527 ISSN: 1796-217X
doi: 10.17706/jsw.11.5.520-527

A Method for Developing Abuse Cases and Its Evaluation

Imano Williams1, Xiaohong Yuan1*, Jeffrey Todd McDonald2, Mohd Anwar1
1Department of Computer Science, North Carolina A&T State University, 1601 East Market St., Greensboro, North Carolina, USA.
2Department of Computer Science, University of South Alabama, 3150 Jaguar Drive, Mobile, Alabama, USA.


Abstract—To develop secure software, software engineers need to have the mindset of attackers. Developing abuse cases can help software engineers to think more like attackers. This paper describes a method for developing abuse cases based on threat modeling, attack patterns, and Common Weakness Enumeration. The method also includes ranking the abuse cases according to their risks. This method intends to help non-experts create abuse cases following a specific process, and leveraging the knowledge bases of threat modeling, attack patterns, and Common Weakness Enumeration. The proposed method was evaluated through two evaluation studies conducted in two secure software engineering courses at two different universities. Evaluation studies show that the proposed method was easier to follow by non-experts in generating abuse cases than brainstorming, and could reduce the time needed for creating abuse cases. Other findings from the evaluation studies are also discussed in the paper.

Index Terms—Abuse cases, threat modeling, attack patterns, common weakness enumeration, secure software development.

[PDF]

Cite: Imano Williams, Xiaohong Yuan, Jeffrey Todd McDonald, Mohd Anwar, "A Method for Developing Abuse Cases and Its Evaluation," Journal of Software vol. 11, no. 5, pp. 520-527, 2016.

General Information

ISSN: 1796-217X (Online)
Frequency: Monthly (2006-2019); Bimonthly (Since 2020)
Editor-in-Chief: Prof. Antanas Verikas
Executive Editor: Ms. Yoyo Y. Zhou
Abstracting/ Indexing: DBLP, EBSCO, Google Scholar, ProQuest, INSPEC, ULRICH's Periodicals Directory, WorldCat, etc
E-mail: jsw@iap.org
  • Dec 06, 2019 News!

    Vol 14, No 1- Vol 14, No 4 has been indexed by EI (Inspec)   [Click]

  • Jun 22, 2020 News!

    Papers published in JSW Vol 14, No 1- Vol 15 No 4 have been indexed by DBLP     [Click]

  • Sep 30, 2020 News!

    The papers published in Vol 15, No 6 have all received dois from Crossref   [Click]

  • Aug 01, 2018 News!

    [CFP] 2020 the annual meeting of JSW Editorial Board, ICCSM 2020, will be held in Rome, Italy, July 17-19, 2020   [Click]

  • Sep 30, 2020 News!

    Vol 15, No 6 has been published with online version     [Click]