Measuring CIA for enterprise applications based on errors classification

مقدم أطروحة جامعية

al-Far, Anas Kamil

مشرف أطروحة جامعية

Qusif, Abd Allah

أعضاء اللجنة

Qasaimih, Malik
Abd Allah, Imad E.
al-Majali, Sufyan

الجامعة

جامعة الأميرة سمية للتكنولوجيا

الكلية

كلية الملك الحسين لعلوم الحوسبة

دولة الجامعة

الأردن

الدرجة العلمية

ماجستير

تاريخ الدرجة العلمية

2016

الملخص الإنجليزي

Confidentiality, Integrity, and Availability (CIA) are principal keys to build any secure software.

Taking those principles into consideration in implementation phases of system development should have an impact on reducing many software vulnerabilities.

The purpose of this thesis is to measure the impact on CIA for any given objectoriented PHP application; by studyingthe impact score on confidentiality, the impact score on integrity, and the impact score on availability fora list of reportedvulnerabilities and its correlation with some code metrics for the given vulnerable source code.

The results indicate that no significant predictive of ‘Confidentiality’ could be obtained from the tested code metrics.

On the other hand, this research uncovered that 23.7% of the variability in ‘Integrity’ was explained by four metrics: Vocabulary Used in Code, Card and Agresti, Intelligent Content, and Efferent Coupling metrics while the Length (Halstead metric) could alone predict about 24.2% of the observed variability in ‘Availability’.

Keywords: Software Security, CIA Model, Confidentiality Score, Integrity Score, Availability Score, Code Characteristics, Code Metrics, Security Metrics, PHP security.

التخصصات الرئيسية

الهندسة الكهربائية

عدد الصفحات

132

قائمة المحتويات

Table of contents.

Abstract.

Abstract in Arabic.

[Chapter One] : Introduction.

[Chapter Two] : Background information and related work.

[Chapter Three] : The proposed model.

[Chapter Four] : Research results and evaluation.

[Chapter Five] : Conclusion and future work.

References.

نمط استشهاد جمعية علماء النفس الأمريكية (APA)

al-Far, Anas Kamil. (2016). Measuring CIA for enterprise applications based on errors classification. (Master's theses Theses and Dissertations Master). Princess Sumaya University for Technology, Jordan
https://search.emarefa.net/detail/BIM-720780

نمط استشهاد الجمعية الأمريكية للغات الحديثة (MLA)

al-Far, Anas Kamil. Measuring CIA for enterprise applications based on errors classification. (Master's theses Theses and Dissertations Master). Princess Sumaya University for Technology. (2016).
https://search.emarefa.net/detail/BIM-720780

نمط استشهاد الجمعية الطبية الأمريكية (AMA)

al-Far, Anas Kamil. (2016). Measuring CIA for enterprise applications based on errors classification. (Master's theses Theses and Dissertations Master). Princess Sumaya University for Technology, Jordan
https://search.emarefa.net/detail/BIM-720780

لغة النص

الإنجليزية

نوع البيانات

رسائل جامعية

رقم السجل

BIM-720780