Computational Evaluation of Software Security Attributes

SEI Report
This paper introduces the CSA approach, provides behavioral requirements for security attributes, and discusses possible application of the CSA approach.
Publisher

Software Engineering Institute

Abstract

In the current state of practice, security properties of software systems are typically assessed through subjective,  labor-intensive human evaluation. Moreover, much of the quantitative security analysis research to date is characterized by the development of approximate solutions and/or based on assumptions that severely constrain the operational utility of the results. In order to achieve a dramatic increase in maturing the discipline of software security engineering, a fundamentally different approach to analysis and evaluation of security attributes is required. The computational security attributes (CSA) approach to software security analysis provides a new approach for specification of security attributes in terms of data and transformation of data by programs. This paper provides an introduction to the CSA approach, provides behavioral requirements for several security attributes, and discusses possible application of the CSA approach to support analysis of security attributes during software development, acquisition, verification, and operation. 

Cite This SEI Report

Walton, G., Longstaff, T., & Linger, R. (2009, June 1). Computational Evaluation of Software Security Attributes. Retrieved September 11, 2026, from https://www.sei.cmu.edu/library/computational-evaluation-of-software-security-attributes/.

@techreport{walton_2009,
author={Walton, Gwendolyn and Longstaff, Thomas and Linger, Richard},
title={Computational Evaluation of Software Security Attributes},
month={Jun},
year={2009},
institution={Software Engineering Institute, Carnegie Mellon University},
url={https://www.sei.cmu.edu/library/computational-evaluation-of-software-security-attributes/},
note={Accessed: 2026-Sep-11}
}

Walton, Gwendolyn, Thomas Longstaff, and Richard Linger. "Computational Evaluation of Software Security Attributes." Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, June 1, 2009. https://www.sei.cmu.edu/library/computational-evaluation-of-software-security-attributes/.

G. Walton, T. Longstaff, and R. Linger, "Computational Evaluation of Software Security Attributes," Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, 1-Jun-2009 [Online]. Available: https://www.sei.cmu.edu/library/computational-evaluation-of-software-security-attributes/. [Accessed: 11-Sep-2026].

Walton, Gwendolyn, Thomas Longstaff, and Richard Linger. "Computational Evaluation of Software Security Attributes." Software Engineering Institute, Carnegie Mellon University, Software Engineering Institute, 1 Jun. 2009. https://www.sei.cmu.edu/library/computational-evaluation-of-software-security-attributes/. Accessed 11 Sep. 2026.

Walton, Gwendolyn; Longstaff, Thomas; & Linger, Richard. Computational Evaluation of Software Security Attributes. Software Engineering Institute. 2009. https://www.sei.cmu.edu/library/computational-evaluation-of-software-security-attributes/