Klocwork had publish a paper on the above title. You can read/access it here.
I won't comments on the paper as it was a good idea/framework they proposed in the paper. The important things I would like to stress here is that the framework or idea is nothing new. It was first established by Microsoft in their SDL. It was already implemented in software development by major software vendor. They might want to re-phrase some of the contents by referring to the giant in doing threat modelling. It does not matter either you are developing normal software or embedded software as it is still treated as a software's project.
0 comments:
Post a Comment