DocumentCode :
3478416
Title :
Mutation Analysis of Magento for Evaluating Threat Model-Based Security Testing
Author :
Thomas, Lijo ; Xu, Weifeng ; Xu, Dianxiang
Author_Institution :
Nat. Center for the Protection of the Financial Infrastruct., Dakota State Univ. Madison, Madison, SD, USA
fYear :
2011
fDate :
18-22 July 2011
Firstpage :
184
Lastpage :
189
Abstract :
Security testing is a major means for assuring software security and many security testing techniques have been developed in the past. Benchmarks, however, are in great demands for empirically evaluating the vulnerability detection capabilities of these techniques. To develop such a benchmark, this paper presents an approach to security mutation analysis of Magento, a fully-fledged open source e-commerce web application for evaluating automated security testing techniques. We create security mutants by injecting vulnerabilities in a systematic way. Specifically, we consider the causes of vulnerabilities according to OWASP´s top 10 web application security risks, the application´s business logic, as well as various consequences of vulnerabilities (i.e., STRIDE attacks). We have created 63 mutants and applied them successfully to the evaluation of two security testing techniques that use threat trees and threat nets as threat models for test generation. Our experiments show that these testing methods can kill most of the mutants but cannot detect the vulnerabilities that are not captured by the threat models.
Keywords :
Internet; electronic commerce; program testing; public domain software; security of data; Magento; OWASP; business logic; open source e-commerce Web application; security mutants; security mutation analysis; software security assurance; test generation; threat model-based security testing; threat nets; threat trees; vulnerability detection; Access control; Authentication; Benchmark testing; Business; Software; Security testing; mutation testing; software testing; threat modeling;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Software and Applications Conference Workshops (COMPSACW), 2011 IEEE 35th Annual
Conference_Location :
Munich
Print_ISBN :
978-1-4577-0980-7
Electronic_ISBN :
978-0-7695-4459-5
Type :
conf
DOI :
10.1109/COMPSACW.2011.40
Filename :
6032235
Link To Document :
بازگشت