SECRHCAug 11, 2020

Identifying Implicit Vulnerabilities through Personas as Goal Models

arXiv:2008.04773v22 citations
AI Analysis

This addresses the issue of misalignment between user and system goals in requirements engineering, though it appears incremental as it builds on existing persona and goal modeling concepts.

The paper tackles the problem of identifying implicit vulnerabilities in systems by reframing personas as social goal models to align user expectations with system goals, resulting in the discovery of previously hidden vulnerabilities in a case study.

When used in requirements processes and tools, personas have the potential to identify vulnerabilities resulting from misalignment between user expectations and system goals. Typically, however, this potential is unfulfilled as personas and system goals are captured with different mindsets, by different teams, and for different purposes. If personas are visualised as goal models, it may be easier for stakeholders to see implications of their goals being satisfied or denied, and designers to incorporate the creation and analysis of such models into the broader RE tool-chain. This paper outlines a tool-supported approach for finding implicit vulnerabilities from user and system goals by reframing personas as social goal models. We illustrate this approach with a case study where previously hidden vulnerabilities based on human behaviour were identified.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes