An empirical evaluation of a language-based security testing technique

  • Authors:
  • Muhammad AboElFotoh;Thomas Dean;Ryan Mayor

  • Affiliations:
  • Queen's University;Queen's University;IBM Canada Ltd.

  • Venue:
  • CASCON '09 Proceedings of the 2009 Conference of the Center for Advanced Studies on Collaborative Research
  • Year:
  • 2009

Quantified Score

Hi-index 0.01

Visualization

Abstract

Security testing of network applications is an essential task that must be carried out prior to the release of software to the market. Since factors such as time-to-market constraints limit the scope or depth of the testing, it is difficult to carry out exhaustive testing prior to the release of the software. As a consequence, flaws may remain undiscovered by the software vendor, which may be discovered by those of malicious intent. In this paper, we report the results of an empirical evaluation of applying a security testing approach and framework, previously tested in an academic setting, to the Distributed Relational Database Architecture (DRDA®) protocol as implemented by the IBM®DB2®Database for Linux®, Unix®, and Windows®product.