Incorporating Verification Standards for Security Requirements Generation from Functional Specifications
Xiaoli Lian, Shuaisong Wang, Hanyu Zou, Fang Liu, Jiajun Wu, Li Zhang
Abstract
In the current software-driven era, ensuring privacy and security is critical. Despite this, the specification of security requirements for software is still largely a manual and labor-intensive process. Engineers are tasked with analyzing potential security threats based on functional requirements (FRs), a procedure prone to omissions and errors due to the expertise gap between cybersecurity experts and software engineers. To bridge this gap, we introduce F2SRD (Function-to-Security Requirements Derivation), an automated approach that proactively derives security requirements (SRs) from functional specifications under the guidance of relevant security verification requirements (VRs) drawn from the well recognized OWASP Application Security Verification Standard (ASVS). F2SRD operates in two main phases: Initially, we develop a VR retriever trained on a custom database of FR-VR pairs, enabling it to adeptly select applicable VRs from ASVS. This targeted retrieval informs the precise and actionable formulation of SRs. Subsequently, these VRs are used to construct structured prompts that direct GPT-4 in generating SRs. Our comparative analysis against two established models demonstrates F2SRD's enhanced performance in producing SRs that excel in inspiration, diversity, and specificity-essential attributes for effective security requirement generation. By leveraging security verification standards, we believe that the generated SRs are not only more focused but also resonate stronger with the needs of engineers.
CCS Concepts: • Software and its engineering → Requirements analysis.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on4
- Promptagator: Few-shot Dense Retrieval From 8 ExamplesZhuyun Dai, Vincent Y. Zhao, Ji Ma, Yi Luan et al.ICLR 2023 · 46 citations
- UDAPDR: Unsupervised Domain Adaptation via LLM Prompting and Distillation of RerankersJon Saad-Falcon, Omar Khattab, Keshav Santhanam, Radu Florian et al.EMNLP 2023 · 23 citations
- On-Demand Security Requirements Synthesis with Relational Generative Adversarial NetworksViktoria Koscinski, Sara Hashemi, Mehdi MirakhorliICSE 2023 · 9 citations
- Enhancing Automated Program Repair with Solution DesignJiuang Zhao, Donghao Yang, Li Zhang, Xiaoli Lian et al.ASE 2024 · 3 citations
Related papers
- PropertyGPT: LLM-driven Formal Verification of Smart Contracts through Retrieval-Augmented Property GenerationYe Liu, Yue Xue, Daoyuan Wu, Yuqiang Sun et al.NDSS 2025
- Light over Heavy: Automated Performance Requirements Quantification with Linguistic InducementShihai Wang, Tao ChenICSE 2026
- NSPG: Natural language Processing-based Security Property Generator for Hardware Security AssuranceXingyu Meng, Amisha Srivastava, Ayush Arunachalam, Avik Ray et al.DAC 2024 · 7 citations
- "It's not my responsibility to write them": An Empirical Study of Software Product Managers and Security RequirementsHouda Naji, Felix Reichmann, Tobias Bruns, M. Angela Sasse et al.USENIX Security 2025
- SecureReviewer: Enhancing Large Language Models for Secure Code Review through Secure-Aware Fine-TuningFang Liu, Simiao Liu, Yinghao Zhu, Xiaoli Lian et al.ICSE 2026
