Overslaan en naar de inhoud gaan

Internship: Making security measurable

Deadline: 02-03-2016 12:00:00

Description

To be or not to be secure. In theory, security is binary. But in practice 100% security does not exist. Instead, security is a continuous battle on many fronts where improvements are obtained gradually. To support such gradual security improvement, we need to be able to measure current security on a continuous scale. But how? The Software Improvement Group has developed multiple security metrics and bundled them in rating mechanisms for software products and processes.

Goals

In this project, you will extend and validate a recently proposed security rating scheme with new measurements in order to capture new aspects of security or make the current metrics more precise or more repeatable. You will study the statistical behaviour of these metrics, test their strengths and weaknesses, and provide us with recommendations of how to integrate them with tools such as Fortify, Checkmarx, INFER.

Suggested reading

What will the work environment look like?

You will be embedded in the Research team of the Software Improvement Group. One of SIG's researchers will be appointed as your daily supervisor. Apart from daily supervision, you will interact with the other researchers on a regular basis. SIG is a dynamic, demanding, and rewarding working environment.

What are our expectations?

Students are expected to perform solid scientific work that is at the same time relevant for practitioners. You will get ample support and supervision and in return we expect you to learn fast and take responsibility for obtaining excellent results.