Characterizing the boundary of security features

Determine where functionality that provides stakeholder value ends and security functionality begins, and characterize the boundaries separating security features from non-security functionality.

Background

Security features may be combined with ordinary functionality and may serve both security and non-security purposes. The paper uses session timeouts as an example: they can prevent session hijacking while also freeing resources in a web application. This creates an unresolved classification problem concerning the nature and boundaries of security features.

References

But where does functionality, which provides value to stakeholders in software systems, end and where does security begin?

The Security Feature Location Problem  (2609.04899 - Hermann et al., 4 Sep 2026) in Section 5, Research Challenges, subsection “C1.1: What constitutes a security feature?”

But how can we determine how far a security feature's implementation extends, and when all of its locations have been found?

The Security Feature Location Problem  (2609.04899 - Hermann et al., 4 Sep 2026) in Section 5, Research Challenges, subsection “C2.3: How can we retroactively obtain the security feature locations needed for security tasks?”