Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Secure by Design: From Insecure to Secure by Design Using Domain Primitives
Jönköping University, School of Engineering, JTH, Department of Computer Science and Informatics.
Jönköping University, School of Engineering, JTH, Department of Computer Science and Informatics.
2024 (English)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE creditsStudent thesis
Abstract [en]

Although it is widely accepted that security in software should never be an afterthought, in many cases, it is. Particularly in the context of legacy codebases, security considerations often take a backseat, pushed back by the pressing demands of functionality, maintenance, and tight development timelines. The very important topic of security is often sidelined or bolted on during the later stages of development, leading to vulnerabilities that could have been avoided with a more proactive approach. Addressing this challenge requires a focus on redesigning legacy code with security as a central concern. This thesis explores the impact of Secure by Design principles, specifically domain primitives, on enhancing software security through a study involving the OWASP(Open Web Application Security Project) Juice Shop, an intentionally insecure web application. The application undergoes a partial redesign where domain primitives are implemented into the legacy code, after which the inbuilt challenge system is used to evaluate the two versions. The redesign of the application employs the Secure by Design principles as detailed by Deogun et al.(2019), aiming to showcase the practical benefits and effectiveness of adopting proactive secure design strategies. The experiment yielded good results that showed the potential of implementing domain primitives into legacy code. However it is clear that it must be accompanied by other security measures to achieve an application that is truly secure by design.

Place, publisher, year, edition, pages
2024. , p. 32
Keywords [en]
secure, design, domain, primitive, owasp, juice, shop, legacy, code
National Category
Computer and Information Sciences
Identifiers
URN: urn:nbn:se:hj:diva-66041OAI: oai:DiVA.org:hj-66041DiVA, id: diva2:1892374
External cooperation
Omegapoint
Subject / course
JTH, Computer Engineering
Supervisors
Examiners
Available from: 2024-09-03 Created: 2024-08-26 Last updated: 2025-10-13Bibliographically approved

Open Access in DiVA

fulltext(554 kB)613 downloads
File information
File name FULLTEXT01.pdfFile size 554 kBChecksum SHA-512
71f945c1dade2541f3b33fb12a379aaf7f35dde0061b430be63fedae47fb648d059f712269a61c060a9c3cd717823b0f38b3038fc362349246d35e86c4d22a41
Type fulltextMimetype application/pdf

By organisation
JTH, Department of Computer Science and Informatics
Computer and Information Sciences

Search outside of DiVA

GoogleGoogle Scholar
Total: 617 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 770 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf