System Security Assurance: A Systematic Literature Review
Ankur Shukla, Basel Katt, Livinus Obiora Nweke, Prosper Kandabongee, Yeng, Goitom Kahsay Weldehawaryat

TL;DR
This paper systematically reviews the current state, challenges, and future directions of system security assurance in ICT and cyber-physical systems, highlighting limitations of existing methods and proposing areas for improvement.
Contribution
It provides a comprehensive analysis of security assurance requirements, processes, and methods, identifying gaps and limitations in current approaches and suggesting future research directions.
Findings
Identified key challenges and gaps in current security assurance methods.
Highlighted limitations of traditional evaluation and certification tools.
Suggested future research directions for improving security assurance.
Abstract
System security assurance provides the confidence that security features, practices, procedures, and architecture of software systems mediate and enforce the security policy and are resilient against security failure and attacks. Alongside the significant benefits of security assurance, the evolution of new information and communication technology (ICT) introduces new challenges regarding information protection. Security assurance methods based on the traditional tools, techniques, and procedures may fail to account new challenges due to poor requirement specifications, static nature, and poor development processes. The common criteria (CC) commonly used for security evaluation and certification process also comes with many limitations and challenges. In this paper, extensive efforts have been made to study the state-of-the-art, limitations and future research directions for security…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Advanced Malware Detection Techniques · Software Reliability and Analysis Research
