Skip to main content
U.S. Department of Energy
Office of Scientific and Technical Information

A code inspection process for security reviews

Journal Article · · Submitted to Journal of Physics Conf.Ser.
OSTI ID:957070

In recent years, it has become more and more evident that software threat communities are taking an increasing interest in Grid infrastructures. To mitigate the security risk associated with the increased numbers of attacks, the Grid software development community needs to scale up effort to reduce software vulnerabilities. This can be achieved by introducing security review processes as a standard project management practice. The Grid Facilities Department of the Fermilab Computing Division has developed a code inspection process, tailored to reviewing security properties of software. The goal of the process is to identify technical risks associated with an application and their impact. This is achieved by focusing on the business needs of the application (what it does and protects), on understanding threats and exploit communities (what an exploiter gains), and on uncovering potential vulnerabilities (what defects can be exploited). The desired outcome of the process is an improvement of the quality of the software artifact and an enhanced understanding of possible mitigation strategies for residual risks. This paper describes the inspection process and lessons learned on applying it to Grid middleware.

Research Organization:
Fermi National Accelerator Laboratory (FNAL), Batavia, IL
Sponsoring Organization:
USDOE
DOE Contract Number:
AC02-07CH11359
OSTI ID:
957070
Report Number(s):
FERMILAB-PUB-09-234-CD
Journal Information:
Submitted to Journal of Physics Conf.Ser., Journal Name: Submitted to Journal of Physics Conf.Ser.
Country of Publication:
United States
Language:
English

Similar Records

Improving Cyber Situational Understanding
Thesis/Dissertation · Wed Aug 20 00:00:00 EDT 2025 · OSTI ID:2584218

Security Vulnerability and Mitigation in Photovoltaic Systems
Conference · Mon Jun 28 00:00:00 EDT 2021 · 2021 IEEE 12th International Symposium on Power Electronics for Distributed Generation Systems (PEDG) · OSTI ID:2341254

Security risk assessment methodology for communities (RAM-C).
Conference · Sun Aug 01 00:00:00 EDT 2004 · OSTI ID:957659