首页> 外文会议>International Conference on Software Security and Reliability >Security Test Generation by Answer Set Programming
【24h】

Security Test Generation by Answer Set Programming

机译:通过答案集编程生成安全测试

获取原文

摘要

Security testing still is a hard task, especially if focusing on non-functional security testing. The two main reasons behind this are, first, at the most a lack of the necessary knowledge required for security testing, second, managing the almost infinite amount of negative test cases, which result from potential security risks. To the best of our knowledge, the issue of the automatic incorporation of security expert knowledge, e.g., known vulnerabilities, exploits and attacks, in the process of security testing is not well considered in the literature. Furthermore, well-known "de facto" security testing approaches, like fuzzing or penetration testing, lack systematic procedures regarding the order of execution of test cases, which renders security testing a cumbersome task. Hence, in this paper we propose a new method for generating negative security tests by logic programming, which applies a risk analysis to establish a set of negative requirements for later test generation.
机译:安全测试仍然是一项艰巨的任务,尤其是在侧重于非功能性安全测试的情况下。其背后的两个主要原因是,第一,至多缺乏安全测试所需的必要知识,第二,管理几乎无限数量的由潜在安全风险引起的负面测试案例。据我们所知,在文献中没有很好地考虑到在安全测试过程中自动合并安全专家知识(例如已知的漏洞,漏洞利用和攻击)的问题。此外,诸如模糊测试或渗透测试之类的众所周知的“事实”安全测试方法缺乏有关测试用例执行顺序的系统程序,这使安全测试成为一项繁琐的任务。因此,在本文中,我们提出了一种通过逻辑编程生成否定性安全测试的新方法,该方法通过进行风险分析来为以后的测试生成建立一套否定要求。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号