Software security assurance of telecommunication systems

Research output: Chapter in Book/Report/Conference proceedingConference article in proceedingsScientificpeer-review

1 Citation (Scopus)

Abstract

In order to obtain evidence about the security strength or performance in software products and telecommunication systems we need automated information security analysis, validation, evaluation and testing approaches. Unfortunately, no widely accepted practical approaches are available. Information security testing of software-intensive and telecommunications systems typically relies heavily on the experience of the security professionals. In this study, we argue that security requirements are within the focus of the information security testing process. Information security requirements can be based on iterative risk, threat and vulnerability analyses, and technical and architectural information. We discuss security testing process, security objectives and security requirements from the basis of the experiences of a security testing case study project.
Original languageEnglish
Title of host publicationProceedings of the 2009 International Conference on Multimedia Computing and Systems, ICMCS 2009
Pages138-143
ISBN (Electronic)978-1-4244-3757-3
DOIs
Publication statusPublished - 2009
MoE publication typeA4 Article in a conference publication
EventInternational Conference on Multimedia Computing and Systems, ICMCS 2009 - Quarzazate, Morocco
Duration: 2 Apr 20094 Apr 2009

Conference

ConferenceInternational Conference on Multimedia Computing and Systems, ICMCS 2009
Abbreviated titleICMCS 2009
CountryMorocco
CityQuarzazate
Period2/04/094/04/09

Fingerprint

Telecommunication systems
Security of data
Testing

Keywords

  • Security assurance
  • Security metrics
  • Security monitoring
  • Security requirements
  • Security testing

Cite this

Savola, R. (2009). Software security assurance of telecommunication systems. In Proceedings of the 2009 International Conference on Multimedia Computing and Systems, ICMCS 2009 (pp. 138-143) https://doi.org/10.1109/MMCS.2009.5256713
Savola, Reijo. / Software security assurance of telecommunication systems. Proceedings of the 2009 International Conference on Multimedia Computing and Systems, ICMCS 2009. 2009. pp. 138-143
@inproceedings{3a45651d814c4d1c84aec4eab0175093,
title = "Software security assurance of telecommunication systems",
abstract = "In order to obtain evidence about the security strength or performance in software products and telecommunication systems we need automated information security analysis, validation, evaluation and testing approaches. Unfortunately, no widely accepted practical approaches are available. Information security testing of software-intensive and telecommunications systems typically relies heavily on the experience of the security professionals. In this study, we argue that security requirements are within the focus of the information security testing process. Information security requirements can be based on iterative risk, threat and vulnerability analyses, and technical and architectural information. We discuss security testing process, security objectives and security requirements from the basis of the experiences of a security testing case study project.",
keywords = "Security assurance, Security metrics, Security monitoring, Security requirements, Security testing",
author = "Reijo Savola",
year = "2009",
doi = "10.1109/MMCS.2009.5256713",
language = "English",
pages = "138--143",
booktitle = "Proceedings of the 2009 International Conference on Multimedia Computing and Systems, ICMCS 2009",

}

Savola, R 2009, Software security assurance of telecommunication systems. in Proceedings of the 2009 International Conference on Multimedia Computing and Systems, ICMCS 2009. pp. 138-143, International Conference on Multimedia Computing and Systems, ICMCS 2009, Quarzazate, Morocco, 2/04/09. https://doi.org/10.1109/MMCS.2009.5256713

Software security assurance of telecommunication systems. / Savola, Reijo.

Proceedings of the 2009 International Conference on Multimedia Computing and Systems, ICMCS 2009. 2009. p. 138-143.

Research output: Chapter in Book/Report/Conference proceedingConference article in proceedingsScientificpeer-review

TY - GEN

T1 - Software security assurance of telecommunication systems

AU - Savola, Reijo

PY - 2009

Y1 - 2009

N2 - In order to obtain evidence about the security strength or performance in software products and telecommunication systems we need automated information security analysis, validation, evaluation and testing approaches. Unfortunately, no widely accepted practical approaches are available. Information security testing of software-intensive and telecommunications systems typically relies heavily on the experience of the security professionals. In this study, we argue that security requirements are within the focus of the information security testing process. Information security requirements can be based on iterative risk, threat and vulnerability analyses, and technical and architectural information. We discuss security testing process, security objectives and security requirements from the basis of the experiences of a security testing case study project.

AB - In order to obtain evidence about the security strength or performance in software products and telecommunication systems we need automated information security analysis, validation, evaluation and testing approaches. Unfortunately, no widely accepted practical approaches are available. Information security testing of software-intensive and telecommunications systems typically relies heavily on the experience of the security professionals. In this study, we argue that security requirements are within the focus of the information security testing process. Information security requirements can be based on iterative risk, threat and vulnerability analyses, and technical and architectural information. We discuss security testing process, security objectives and security requirements from the basis of the experiences of a security testing case study project.

KW - Security assurance

KW - Security metrics

KW - Security monitoring

KW - Security requirements

KW - Security testing

U2 - 10.1109/MMCS.2009.5256713

DO - 10.1109/MMCS.2009.5256713

M3 - Conference article in proceedings

SP - 138

EP - 143

BT - Proceedings of the 2009 International Conference on Multimedia Computing and Systems, ICMCS 2009

ER -

Savola R. Software security assurance of telecommunication systems. In Proceedings of the 2009 International Conference on Multimedia Computing and Systems, ICMCS 2009. 2009. p. 138-143 https://doi.org/10.1109/MMCS.2009.5256713