Browse > Article

A Study of Web Application Security Quality Architecture Management Process referenced ISO/IEC9000 Model  

Kim, Jeom-Goo (남서울대학교 컴퓨터학과)
Noh, Si-Choon (남서울대학교 컴퓨터학과)
Lee, Do-Hyeon (남서울대학교 IT융합기술사업단)
Publication Information
Abstract
According to ISO/IEC 9000, quality to satisfy users' requirements when using the product or service is defined as the characteristics of the synthesized concept. Secure web application coding information systems with the reliability and quality of service is one of the determining factor. Secure coding in order to achieve the quality based on the model is necessary. The reason is that the security is in quality properties in the range of non-functional requirements that necessitates. Secure coding for the design of quality systems based on the quality of the definition of quality attributes, quality requirements, quality attribute scenarios are defined, and must be set. To this end, referring to IEEE 1061 quality model for web application, quality model structure is developed. Secure web application architecture design is composed of coding quality of the model systems, web applications draw interest to stakeholders, decision drivers secure coding architecture, quality attributes, eliciting quality requirements of the security settings, creating web application architecture descriptions and security framework.
Keywords
Security Quality; ISO/IEC9000; Web Application; Design Process;
Citations & Related Records
연도 인용수 순위
  • Reference
1 ISO/IEC 9126, http:// blog.naver.com/khnplus/100019286775
2 아키텍트와이노베이터.http://naver.com/.
3 IEEE Std. 1971 (Recommended Practice for Arch itectural Description of Software-Intensive Syste ms), 2000.10
4 Technical Report CMR/ SEI-95-Tr-021, 1995
5 "Architecture: From Prehistory to Post -Modern ismn Software Architecture in Practice Second Ed,1923
6 ISO/IEC 9000, http:// blog.naver.
7 OWASP, http://www.owasp.org
8 http://www.krcert.or.kr/index.jsp
9 김점구,노시춘, Injection Flaws를 중심으로한 웹 애플리케이션 취약점 진단시스템 개발 모델,2012.3
10 이미정,노시춘, SQL Injection 취약점 진단 프로그램,2005.6
11 진영승, "인터넷에서의 해킹기법과 보안방법에 관한 조사 분석", 연세대 관리과학대학원 석사논문,2010
12 윤준, "최신 웹 해킹기법에 대한 분석과 대응방법",한국정보보호진흥원기반보호기획팀.2010