Towards Improved Network Security Requirements and Policy: Domain-Specific Completeness Analysis via Topic Modeling
Title | Towards Improved Network Security Requirements and Policy: Domain-Specific Completeness Analysis via Topic Modeling |
Publication Type | Conference Paper |
Year of Publication | 2020 |
Authors | Hayes, J. Huffman, Payne, J., Essex, E., Cole, K., Alverson, J., Dekhtyar, A., Fang, D., Bernosky, G. |
Conference Name | 2020 IEEE Seventh International Workshop on Artificial Intelligence for Requirements Engineering (AIRE) |
Date Published | Sept. 2020 |
Publisher | IEEE |
ISBN Number | 978-1-7281-8352-7 |
Keywords | Communication networks, Communication system security, completeness, empirical evaluation, Loading, machine learning, Network security, policy-based governance, pubcrawl, Requirements quality, security, security policies, Semantics, Text recognition, wireless networks |
Abstract | Network security policies contain requirements - including system and software features as well as expected and desired actions of human actors. In this paper, we present a framework for evaluation of textual network security policies as requirements documents to identify areas for improvement. Specifically, our framework concentrates on completeness. We use topic modeling coupled with expert evaluation to learn the complete list of important topics that should be addressed in a network security policy. Using these topics as a checklist, we evaluate (students) a collection of network security policies for completeness, i.e., the level of presence of these topics in the text. We developed three methods for topic recognition to identify missing or poorly addressed topics. We examine network security policies and report the results of our analysis: preliminary success of our approach. |
URL | https://ieeexplore.ieee.org/document/9233035 |
DOI | 10.1109/AIRE51212.2020.00019 |
Citation Key | hayes_towards_2020 |