Write a Blog >>
ESEC/FSE 2022
Mon 14 - Fri 18 November 2022 Singapore
Fri 18 Nov 2022 15:00 - 15:20 at Town Plaza GLR - Prediction Models

Security is getting substantial focus in many industries, especially safety-critical ones. When new regulations and standards which can run to hundreds of pages are introduced, it is necessary to identify the requirements in those documents which have an impact on security. Additionally, it is necessary to revisit the requirements of existing systems and identify the security-related ones. We investigate the feasibility of using a classifier for security-related requirements trained on requirement specifications available online. We base our investigation on 15 requirement documents, randomly selected and partially pre-labeled, with a total of 3,880 requirements. To validate the model, we run a cross-project prediction on the data where each specification constitutes a group. We also test the model on three different UN regulations from the automotive domain with different magnitudes of security relevance. Our results indicate the feasibility of training a model from a heterogeneous data set including specifications from multiple domains and in different styles. Additionally, we show the ability of such a classifier to identify security requirements in real-life regulations and discuss scenarios in which such classification becomes useful to practitioners.

Fri 18 Nov

Displayed time zone: Beijing, Chongqing, Hong Kong, Urumqi change

14:00 - 15:30
Prediction ModelsPROMISE at Town Plaza GLR
14:00
20m
Research paper
Improving the Performance of Code Vulnerability Prediction using Abstract Syntax Tree Information
PROMISE
Fahad Al Debeyan Lancaster University, Tracy Hall Lancaster University, David Bowes Lancaster University
14:20
20m
Research paper
Feature sets in just-in-time defect prediction: An empirical evaluation
PROMISE
Peter Bludau fortiss GmbH, Alexander Pretschner Technical University of Munich
14:40
20m
Research paper
Predicting Build Outcomes In Continuous Integration Using Textual Analysis of Source Code Commits
PROMISE
Khaled Al-Sabbagh University of Gothenburg, Miroslaw Staron University of Gothenburg, Regina Hebig University of Gothenburg
15:00
20m
Research paper
Identifying security-related requirements in regulatory documents based on cross-project classification
PROMISE
Mazen Mohamad Chalmers and University of Gothenburg, Jan-Philipp Steghöfer XITASO GmbH IT & Software Solutions, Alexander Åström Volvo GTT, Riccardo Scandariato Hamburg University of Technology