Computational Evaluation of Software Security Attributes
• SEI Report
Publisher
Software Engineering Institute
Abstract
In the current state of practice, security properties of software systems are typically assessed through subjective, labor-intensive human evaluation. Moreover, much of the quantitative security analysis research to date is characterized by the development of approximate solutions and/or based on assumptions that severely constrain the operational utility of the results. In order to achieve a dramatic increase in maturing the discipline of software security engineering, a fundamentally different approach to analysis and evaluation of security attributes is required. The computational security attributes (CSA) approach to software security analysis provides a new approach for specification of security attributes in terms of data and transformation of data by programs. This paper provides an introduction to the CSA approach, provides behavioral requirements for several security attributes, and discusses possible application of the CSA approach to support analysis of security attributes during software development, acquisition, verification, and operation.
Cite This SEI Report
Walton, G., Longstaff, T., & Linger, R. (2009, June 1). Computational Evaluation of Software Security Attributes. Retrieved September 11, 2026, from https://www.sei.cmu.edu/library/computational-evaluation-of-software-security-attributes/.
@techreport{walton_2009,
author={Walton, Gwendolyn and Longstaff, Thomas and Linger, Richard},
title={Computational Evaluation of Software Security Attributes},
month={Jun},
year={2009},
institution={Software Engineering Institute, Carnegie Mellon University},
url={https://www.sei.cmu.edu/library/computational-evaluation-of-software-security-attributes/},
note={Accessed: 2026-Sep-11}
}
Walton, Gwendolyn, Thomas Longstaff, and Richard Linger. "Computational Evaluation of Software Security Attributes." Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, June 1, 2009. https://www.sei.cmu.edu/library/computational-evaluation-of-software-security-attributes/.
G. Walton, T. Longstaff, and R. Linger, "Computational Evaluation of Software Security Attributes," Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, 1-Jun-2009 [Online]. Available: https://www.sei.cmu.edu/library/computational-evaluation-of-software-security-attributes/. [Accessed: 11-Sep-2026].
Walton, Gwendolyn, Thomas Longstaff, and Richard Linger. "Computational Evaluation of Software Security Attributes." Software Engineering Institute, Carnegie Mellon University, Software Engineering Institute, 1 Jun. 2009. https://www.sei.cmu.edu/library/computational-evaluation-of-software-security-attributes/. Accessed 11 Sep. 2026.
Walton, Gwendolyn; Longstaff, Thomas; & Linger, Richard. Computational Evaluation of Software Security Attributes. Software Engineering Institute. 2009. https://www.sei.cmu.edu/library/computational-evaluation-of-software-security-attributes/