vix.ing · top · new · best · stats · spec

Methods and models for identifying threats at the design stage of information systems

2025/01/07 by Rustamov, Doniyor

paper · doi:10.34920/icdgpdt.34

Abstract

This article examines cybersecurity issues that affect the efficient and fully functional operation of information systems which have rapidly integrated into human activities today. It analyzes approaches to identifying and eliminating cybersecurity threats not only during the creation of information systems but also at the stage of their architecture formation. The application of STRIDE, CWE, and OWASP methodologies and their shortcomings are highlighted. It should be noted that a comprehensive analysis and description of the information system`s services in threat modeling leads to the maximum formalization of potential threats. It is known that the software development lifecycle is recognized as a standard for all programmers. However, cybersecurity experts acknowledge that even in this scheme, there are insufficient stages that account for all cybersecurity threats. To address this, it is proposed to identify cybersecurity threats at the initial stages and define measures to eliminate them by introducing additional processes into the lifecycle of SDLC information system development. In this regard, it is important to develop a metamodel of information system elements and formalize the forms of activity.

Related