Uppsats
A Multi-Agent Approach for a Security-Aware Translation of Software Business Requirements
Magister-uppsats
Blekinge Tekniska Högskola/Institutionen för programvaruteknik
Publicerad: 2026
Språk: Engelska
Nyckelord
klicka för att sökaSammanfattning
Context. The translation of high-level business requirements into detailed, security-compliant software specifications is a critical yet often neglected phase of the software development lifecycle. Traditional Security Requirements Engineering (SRE) is frequently manual, error-prone, and disconnected from the rapid pace of modern development, creating a "translation gap" that leaves software vulnerable to security threats. Objectives. In this study, we investigate how a Multi-Agent System (MAS) powered by Large Language Models (LLMs) can automate this translation process. The primary objective is to design and validate an architecture that systematically bridges the gap between abstract business needs and actionable security controls, ensuring alignment with industry standards such as OWASP ASVS, NIST SP 800-53, and ISO 27001. Methods. Following a Design Science Research Process (DSRP) methodology, a prototype system comprising ten specialized agents was developed, utilizing Retrieval-Augmented Generation (RAG) to ground outputs in verified security knowledge. The system was empirically evaluated through 14 industrial use case generations and validated via a survey of 15 software engineering experts who assessed the utility and quality of the generated security reports. Results. The automated system achieved a mean quality score of 0.85 out of 1.0, with particularly high performance in consistency (0.91) and standards alignment (0.89). The parallel execution of specialized agents reduced analysis time by approximately 40% compared to sequential processes. Expert practitioners reported a high intent to adopt the system (4.13/5), confirming its practical utility, though feedback indicated a need for better integration with development tools to improve implementability. Conclusions. We conclude that decomposing SRE tasks into specialized agent roles significantly enhances the reliability and efficiency of security analysis compared to generic LLM approaches. We also conclude that the integration of RAG is essential for preventing hallucinations and ensuring factual compliance. Moreover, while the generation of requirements is effectively solved, future work must address the direct integration of these agents into DevSecOps pipelines to fully realize "Shift Left" security.
Information
- Författare
- Mantzouranidis, Savvas
- Lärosäte / institution
- Blekinge Tekniska Högskola/Institutionen för programvaruteknik
- Publiceringsdatum
- 2026
- Uppsatstyp
- Magister-uppsats
- Språk
- Engelska
Utforska vidare
Liknande uppsatser
Uppsatser med liknande ämnen och nyckelord.
Master-uppsats, Högskolan Dalarna/Institutionen för information och teknik
Gyawali, Dhiraj, Hettiarachchi, Amila
Publicerad: 2026
Magister-uppsats, Mälardalens universitet/Institutionen för datavetenskap och datateknik
Lazovic, Nikola
Publicerad: 2026
Yrkesexamen på avancerad nivå, Uppsala universitet/Avdelningen för systemteknik
Vigholm, Albin
Publicerad: 2026
Kandidat-uppsats, Högskolan i Skövde/Institutionen för informationsteknologi
Dargren, Calle
Publicerad: 2026
Kandidat-uppsats, Jönköping University/Tekniska Högskolan
Rönnqvist, Emilia, Skoogh, Lovisa
Publicerad: 2026
Master-uppsats, KTH/Skolan för elektroteknik och datavetenskap (EECS)
Saleh, Abdelrahman
Publicerad: 2026