Skip to main navigation Skip to search Skip to main content

Secure Software by Design from an Adversary Perspective

  • Mariyam Zehra

Student thesis: Master's Thesis

Abstract

The increasing reliance on software systems across critical domains has significantly amplified the impact of security vulnerabilities, many of which originate from underlying architectural design flaws rather than isolated implementation errors. Traditional cybersecurity approaches remain largely reactive, focusing on patching vulnerabilities after deployment, which often fails to address their root causes. This has led to a growing emphasis on proactive, secure-by-design methodologies that integrate security considerations throughout the Software Development Lifecycle (SDLC). This research proposes an adversary-centric architectural mapping framework that systematically links software vulnerabilities to their underlying security design principles and corresponding secure design patterns. The framework leverages structured vulnerability knowledge bases, including Common Weakness Enumeration (CWE), to identify how adversarial tactics, techniques, and procedures (TTPs) exploit design-level weaknesses. By establishing traceable relationships between vulnerabilities, design principles, and architectural mitigation strategies, the proposed approach enables proactive security decision-making at the design stage. To evaluate the effectiveness of the framework, a curated dataset of 46 hardware and software CWEs was analysed and mapped to relevant security principles and design patterns, supported by expert validation. In addition, the study investigates the capability of contemporary Large Language Models (LLMs) to reproduce expert-driven architectural reasoning by generating mitigation recommendations based on vulnerability descriptions. The performance of these models was assessed using defined evaluation metrics, including pattern-level and principle-level alignment. The findings demonstrate that while LLMs show promising capabilities in identifying vulnerability characteristics, they often struggle to capture deeper architectural relationships and root-cause reasoning required for secure system design. The research highlights the importance of structured, principle-driven methodologies in bridging the gap between threat intelligence and architectural security practices. Overall, this study contributes to the field of secure software design by introducing a unified framework that integrates adversarial perspectives with architectural mitigation strategies, while also providing empirical insights into the limitations and potential of AI-assisted security analysis.
Date of Award8 Jul 2026
Original languageEnglish
SupervisorGary Allen (Main Supervisor) & Simon Parkinson (Co-Supervisor)

Cite this

'