Using implied scenarios in security testing

  • Authors:
  • Sarah Al-Azzani;Rami Bahsoon

  • Affiliations:
  • University of Birmingham, Edgbaston, Birmingham, UK;University of Birmingham, Edgbaston, Birmingham, UK

  • Venue:
  • Proceedings of the 2010 ICSE Workshop on Software Engineering for Secure Systems
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

Existing security testing techniques often fail to reveal critical security threats, partly because testers focus on testing known and expected behaviours, and consequently, ignore testing for unspecified behaviours that are frequently targeted by attackers. The novel contribution of this paper is an exploratory example of the use of Implied Scenarios detection to the problem of security testing. Implied scenarios arise when the desired global behaviour is implemented component-wise. These scenarios can have security consequences on the system, and thus provide useful feedback for the security posture of the system. We introduce the application of Implied Scenario detection for security testing to reveal unexpected interactions between system components. We motivate its need by drawing on the limitations of existing work on testing for security. We adapt a model-driven approach to guide the testing process. We use an example to illustrate the feasibility and the applicability of the suggestion, and for evaluating its potential benefits.