Analyzing the security of C# source code using a hierarchical quality model

dc.contributor.advisorChairperson, Graduate Committee: Clemente Izurietaen
dc.contributor.authorHarrison, Payton Raeen
dc.date.accessioned2023-01-27T13:38:46Z
dc.date.available2023-01-27T13:38:46Z
dc.date.issued2022en
dc.description.abstractIn software engineering, both in government and in industry, there are no universal standards or guidelines for security or quality. There is an increased need for evaluating the security of source code projects, which is made apparent by the number of real-world cyber attacks that have taken place recently. Our research goal is to design and develop a security quality model that helps stakeholders assess the security of C# source code projects. While there are many analysis tools that can be used to identity security vulnerabilities, the use of a model is beneficial in integrating multiple analysis tools to have better coverage over the number of security vulnerabilities detected (compared to the use of a single tool) and to aggregate these vulnerabilities upward into a broader security quality context. We accomplished our goal by developing and validating a hierarchical security quality model (PIQUE-C#-Sec) to evaluate the security quality of software written in C#. This model is an operationalized model using PIQUE, or the Platform for Investigative software Quality Understanding and Evaluation. PIQUE-C#-Sec improves upon previous security quality models and quality models that precede it by focusing on being specific, flexible, and extensible. This thesis introduces the model design for PIQUE-C#-Sec and examines the results from the efforts of validating the PIQUE-C#-Sec model. This model was validated using sensitivity analysis, which consisted of collecting data on benchmark repositories and observing if and how the PIQUE-C#-Sec model output varied as a function of these repository attributes. Additionally, the model was analyzed by testing to see how the PIQUE-C#-Sec model node values changed because of the tools reporting additional vulnerabilities. Based on these results, we conclude that the PIQUE-C#-Sec model is effective for stakeholders to use when evaluating C# source code, and the model can be used as a security quality gate for evaluating these projects.en
dc.identifier.urihttps://scholarworks.montana.edu/handle/1/17385en
dc.language.isoenen
dc.publisherMontana State University - Bozeman, College of Engineeringen
dc.rights.holderCopyright 2022 by Payton Rae Harrisonen
dc.subject.lcshC# (Computer program language)en
dc.subject.lcshSoftware engineeringen
dc.subject.lcshComputer securityen
dc.subject.lcshEvaluationen
dc.titleAnalyzing the security of C# source code using a hierarchical quality modelen
dc.typeThesisen
mus.data.thumbpage28en
thesis.degree.committeemembersMembers, Graduate Committee: Ann Marie Reinhold; Reimanis, Dereken
thesis.degree.departmentComputing.en
thesis.degree.genreThesisen
thesis.degree.nameMSen
thesis.format.extentfirstpage1en
thesis.format.extentlastpage120en

Files

Original bundle

Now showing 1 - 1 of 1
Thumbnail Image
Name:
harrison-analyzing-2022.pdf
Size:
3.14 MB
Format:
Adobe Portable Document Format
Description:
Analyzing the security of C# source code using a hierarchical quality model (PDF)

License bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.71 KB
Format:
Plain Text
Description:
Copyright (c) 2002-2022, LYRASIS. All rights reserved.