DocumentCode
2351641
Title
Practical Experience Gained from Passive Testing of Web Based Systems
Author
Bagnato, Alessandra ; Raiteri, Fabio ; Mallouli, Wissam ; Wehbi, Bachar
Author_Institution
Corp. Res. Divisions, TXT e-solutions, Genoa, Italy
fYear
2010
fDate
6-10 April 2010
Firstpage
394
Lastpage
402
Abstract
In recent years Web-based systems have become extremely popular and, nowadays, they are used in critical environments such as financial, medical, and military systems. As the use of Web applications for security-critical services has increased, the number and sophistication of attacks against these applications have grown as well. For this reason it is essential to be able to prove that the target Web-based system implements its designed security requirements avoiding known vulnerabilities in HTTP-based solutions. To reach this aim, we can rely on several testing techniques and mainly on security passive testing approach that is becoming increasingly important to security-relevant aspects into web based software systems. This article describes the application of the TestInv-P passive testing tool as part of the testing phase of TXT e-tourism Web application. TestInv-P is a passive testing tool that monitors communication traces of an application during run-time and verifies whether it satisfies certain security-related invariants derived from SHIELDS models.
Keywords
Internet; program testing; safety-critical software; security of data; software tools; HTTP based solution; SHIELDS model; TXT e- tourism Web application; Testlnv-P passive testing tool; Web based software; security critical service; security related invariant; Application software; Communication system security; Computer network management; Protocols; Real time systems; Runtime; Software systems; Software testing; System testing; Telecommunication network management; Web based application; invariants; passive testing; practical experience; security requirements;
fLanguage
English
Publisher
ieee
Conference_Titel
Software Testing, Verification, and Validation Workshops (ICSTW), 2010 Third International Conference on
Conference_Location
Paris
Print_ISBN
978-1-4244-6773-0
Type
conf
DOI
10.1109/ICSTW.2010.39
Filename
5463676
Link To Document