DocumentCode :
2013940
Title :
Training Security Assurance Teams Using Vulnerability Injection
Author :
Fonseca, J. ; Vieira, Marco ; Madeira, Henrique ; Henrique, M.
Author_Institution :
CISUC, Polithecnic Inst. of Guarda, Guarda, Portugal
fYear :
2008
fDate :
15-17 Dec. 2008
Firstpage :
297
Lastpage :
304
Abstract :
Writing secure Web applications is a complex task. In fact, a vast majority of Web applications are likely to have security vulnerabilities that can be exploited using simple tools like a common Web browser. This represents a great danger as the attacks may have disastrous consequences to organizations, harming their assets and reputation. To mitigate these vulnerabilities, security code inspections and penetration tests must be conducted by well-trained teams during the development of the application. However, effective code inspections and testing takes time and cost a lot of money, even before any business revenue. Furthermore, software quality assurance teams typically lack the knowledge required to effectively detect security problems. In this paper we propose an approach to quickly and effectively train security assurance teams in the context of web application development. The approach combines a novel vulnerability injection technique with relevant guidance information about the most common security vulnerabilities to provide a realistic training scenario. Our experimental results show that a short training period is sufficient to clearly improve the ability of security assurance teams to detect vulnerabilities during both code inspections and penetration tests.
Keywords :
Internet; security of data; software quality; Web browser; code inspections; penetration tests; software quality assurance; training security assurance teams; vulnerability injection technique; Application software; Costs; Data security; Information security; Inspection; Performance evaluation; Quality assurance; Software quality; Testing; Writing; Security; Training; Vulnerability Injection;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Dependable Computing, 2008. PRDC '08. 14th IEEE Pacific Rim International Symposium on
Conference_Location :
Taipei
Print_ISBN :
978-0-7695-3448-0
Electronic_ISBN :
978-0-7695-3448-0
Type :
conf
DOI :
10.1109/PRDC.2008.43
Filename :
4725309
Link To Document :
بازگشت