Linguistic security testing for text communication protocols

  • Authors:
  • Ben W. Y. Kam;Thomas R. Dean

  • Affiliations:
  • School of Computing, Queen's University, Kingston, Canada;Electrical and Computer Engineering, Queen's University, Kingston, Canada

  • Venue:
  • TAIC PART'10 Proceedings of the 5th international academic and industrial conference on Testing - practice and research techniques
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

We introduce a new Syntax-based Security Testing (SST) framework that uses a protocol specification to perform security testing on text-based communication protocols. A protocol specification of a particular text-based protocol under-tested represents its syntactic grammar and static constraints. The specification is used to generate test cases by mutating valid messages, breaking the syntactic and constraints of the protocol. The framework is demonstrated using a toy Web application and the open source application KOrganizer.