Software security vulnerability testing in hostile environments

  • Authors:
  • Herbert H. Thompson;James A. Whittaker;Florence E. Mottay

  • Affiliations:
  • Florida Institute of Technology, Melbourne, Florida;Florida Institute of Technology, Melbourne, Florida;Florida Institute of Technology, Melbourne, Florida

  • Venue:
  • Proceedings of the 2002 ACM symposium on Applied computing
  • Year:
  • 2002

Quantified Score

Hi-index 0.00

Visualization

Abstract

Traditional Black box software testing can be effective at exposing some classes of software failures. Security class failures, however, do not tend to manifest readily using these techniques. The problem is that many security failures occur in stressed environments, which appear in the field, but are often neglected during testing because of the difficulty to simulate these conditions. Software can only be considered secure if it behaves securely under all operating environments. Hostile environment testing must thus be a part of any overall testing strategy. This paper describes this necessity and a black box approach for creating such environments in order to expose security vulnerabilities.