DocumentCode :
2351641
Title :
Practical Experience Gained from Passive Testing of Web Based Systems
Author :
Bagnato, Alessandra ; Raiteri, Fabio ; Mallouli, Wissam ; Wehbi, Bachar
Author_Institution :
Corp. Res. Divisions, TXT e-solutions, Genoa, Italy
fYear :
2010
fDate :
6-10 April 2010
Firstpage :
394
Lastpage :
402
Abstract :
In recent years Web-based systems have become extremely popular and, nowadays, they are used in critical environments such as financial, medical, and military systems. As the use of Web applications for security-critical services has increased, the number and sophistication of attacks against these applications have grown as well. For this reason it is essential to be able to prove that the target Web-based system implements its designed security requirements avoiding known vulnerabilities in HTTP-based solutions. To reach this aim, we can rely on several testing techniques and mainly on security passive testing approach that is becoming increasingly important to security-relevant aspects into web based software systems. This article describes the application of the TestInv-P passive testing tool as part of the testing phase of TXT e-tourism Web application. TestInv-P is a passive testing tool that monitors communication traces of an application during run-time and verifies whether it satisfies certain security-related invariants derived from SHIELDS models.
Keywords :
Internet; program testing; safety-critical software; security of data; software tools; HTTP based solution; SHIELDS model; TXT e- tourism Web application; Testlnv-P passive testing tool; Web based software; security critical service; security related invariant; Application software; Communication system security; Computer network management; Protocols; Real time systems; Runtime; Software systems; Software testing; System testing; Telecommunication network management; Web based application; invariants; passive testing; practical experience; security requirements;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Software Testing, Verification, and Validation Workshops (ICSTW), 2010 Third International Conference on
Conference_Location :
Paris
Print_ISBN :
978-1-4244-6773-0
Type :
conf
DOI :
10.1109/ICSTW.2010.39
Filename :
5463676
Link To Document :
بازگشت