Visible to the public Towards Improved Network Security Requirements and Policy: Domain-Specific Completeness Analysis via Topic Modeling

TitleTowards Improved Network Security Requirements and Policy: Domain-Specific Completeness Analysis via Topic Modeling
Publication TypeConference Paper
Year of Publication2020
AuthorsHayes, J. Huffman, Payne, J., Essex, E., Cole, K., Alverson, J., Dekhtyar, A., Fang, D., Bernosky, G.
Conference Name2020 IEEE Seventh International Workshop on Artificial Intelligence for Requirements Engineering (AIRE)
Date PublishedSept. 2020
PublisherIEEE
ISBN Number978-1-7281-8352-7
KeywordsCommunication networks, Communication system security, completeness, empirical evaluation, Loading, machine learning, Network security, policy-based governance, pubcrawl, Requirements quality, security, security policies, Semantics, Text recognition, wireless networks
Abstract

Network security policies contain requirements - including system and software features as well as expected and desired actions of human actors. In this paper, we present a framework for evaluation of textual network security policies as requirements documents to identify areas for improvement. Specifically, our framework concentrates on completeness. We use topic modeling coupled with expert evaluation to learn the complete list of important topics that should be addressed in a network security policy. Using these topics as a checklist, we evaluate (students) a collection of network security policies for completeness, i.e., the level of presence of these topics in the text. We developed three methods for topic recognition to identify missing or poorly addressed topics. We examine network security policies and report the results of our analysis: preliminary success of our approach.

URLhttps://ieeexplore.ieee.org/document/9233035
DOI10.1109/AIRE51212.2020.00019
Citation Keyhayes_towards_2020