Background: Organizations are experiencing an increasing demand for security-by-design activities (e.g., STRIDE analyses) which require a high manual effort. This situation is worsened by the current lack of diverse (and sufficient) security workforce and inconclusive results from past studies. To date, the deciding human factors (e.g., diversity dimensions) that play a role in threat analysis have not been sufficiently explored. Objective: To address this issue, we plan to conduct a series of exploratory controlled experiments. The main objective is to empirically measure the human-aspects that play a role in threat analysis alongside the more well-known measures of analysis performance. Method: We design the experiments as a differentiated replication of past experiments with STRIDE. The replication design is aimed at capturing some similar measures (e.g., of outcome quality) and additional measures (e.g., diversity dimensions). We plan to conduct the experiments in an academic setting. Limitations: Obtaining a balanced population (e.g., wrt gender) in advanced computer science courses is not realistic. The experiments we plan to conduct with MSc level students will certainly suffer this limitation.
翻译:目标:为了解决这一问题,我们计划进行一系列探索性控制实验,主要目标是实证地衡量在威胁分析中发挥作用的人类阶层,同时采用更著名的分析性能措施。方法:我们设计这些实验,以区别地复制过去与STREIDE进行的实验。复制设计旨在捕捉一些类似的措施(例如结果质量)和额外措施(例如多样性方面)。我们计划在学术环境中进行实验。限制:在高级计算机科学课程中取得平衡的人口(例如,wrt性别)是不现实的。我们计划与MSC级学生进行的实验肯定会受到这种限制。