Incorporating Verification Standards for Security Requirements Generation from Functional Specifications
Xiaoli Lian, Shuaisong Wang, Hanyu Zou, Fang Liu, Jiajun Wu, Li Zhang
摘要
In the current software-driven era, ensuring privacy and security is critical. Despite this, the specification of security requirements for software is still largely a manual and labor-intensive process. Engineers are tasked with analyzing potential security threats based on functional requirements (FRs), a procedure prone to omissions and errors due to the expertise gap between cybersecurity experts and software engineers. To bridge this gap, we introduce F2SRD (Function-to-Security Requirements Derivation), an automated approach that proactively derives security requirements (SRs) from functional specifications under the guidance of relevant security verification requirements (VRs) drawn from the well recognized OWASP Application Security Verification Standard (ASVS). F2SRD operates in two main phases: Initially, we develop a VR retriever trained on a custom database of FR-VR pairs, enabling it to adeptly select applicable VRs from ASVS. This targeted retrieval informs the precise and actionable formulation of SRs. Subsequently, these VRs are used to construct structured prompts that direct GPT-4 in generating SRs. Our comparative analysis against two established models demonstrates F2SRD's enhanced performance in producing SRs that excel in inspiration, diversity, and specificity-essential attributes for effective security requirement generation. By leveraging security verification standards, we believe that the generated SRs are not only more focused but also resonate stronger with the needs of engineers.
CCS Concepts: • Software and its engineering → Requirements analysis.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper4
- Promptagator: Few-shot Dense Retrieval From 8 ExamplesZhuyun Dai, Vincent Y. Zhao, Ji Ma, Yi Luan 等ICLR 2023 · 被引用 46 次
- UDAPDR: Unsupervised Domain Adaptation via LLM Prompting and Distillation of RerankersJon Saad-Falcon, Omar Khattab, Keshav Santhanam, Radu Florian 等EMNLP 2023 · 被引用 23 次
- On-Demand Security Requirements Synthesis with Relational Generative Adversarial NetworksViktoria Koscinski, Sara Hashemi, Mehdi MirakhorliICSE 2023 · 被引用 9 次
- Enhancing Automated Program Repair with Solution DesignJiuang Zhao, Donghao Yang, Li Zhang, Xiaoli Lian 等ASE 2024 · 被引用 3 次
相关 Paper
- PropertyGPT: LLM-driven Formal Verification of Smart Contracts through Retrieval-Augmented Property GenerationYe Liu, Yue Xue, Daoyuan Wu, Yuqiang Sun 等NDSS 2025
- Light over Heavy: Automated Performance Requirements Quantification with Linguistic InducementShihai Wang, Tao ChenICSE 2026
- NSPG: Natural language Processing-based Security Property Generator for Hardware Security AssuranceXingyu Meng, Amisha Srivastava, Ayush Arunachalam, Avik Ray 等DAC 2024 · 被引用 7 次
- "It's not my responsibility to write them": An Empirical Study of Software Product Managers and Security RequirementsHouda Naji, Felix Reichmann, Tobias Bruns, M. Angela Sasse 等USENIX Security 2025
- SecureReviewer: Enhancing Large Language Models for Secure Code Review through Secure-Aware Fine-TuningFang Liu, Simiao Liu, Yinghao Zhu, Xiaoli Lian 等ICSE 2026
