DocumentCode :
3642342
Title :
Search-Based Application Security Testing: Towards a Structured Search Space
Author :
Sven Türpe
Author_Institution :
Fraunhofer Inst. for Secure Inf. Technol. (SIT), Darmstadt, Germany
fYear :
2011
fDate :
3/1/2011 12:00:00 AM
Firstpage :
198
Lastpage :
201
Abstract :
This position paper outlines a staged approach to search-based application security testing. In the first stage one searches for candidate tests in the input space that have a chance of leading to good security tests. In the second stage one selects individual candidates and uses them to select and parametrize specialized search techniques. This approach has its roots in exploratory security testing. In the first stage, the fitness of tests depends on their ability to provoke vulnerability symptoms at all, and on their relation to other tests in a test suite. In the second stage, the fittest tests are those that come closest to an exploit of a specific type of vulnerability. To evaluate the performance of such a staged approach one might use web application vulnerability scanners as a baseline.
Keywords :
"Security","Software","Conferences","Space exploration","Software testing","Software engineering"
Publisher :
ieee
Conference_Titel :
Software Testing, Verification and Validation Workshops (ICSTW), 2011 IEEE Fourth International Conference on
Print_ISBN :
978-1-4577-0019-4
Type :
conf
DOI :
10.1109/ICSTW.2011.96
Filename :
5954410
Link To Document :
بازگشت