• DocumentCode
    3642342
  • Title

    Search-Based Application Security Testing: Towards a Structured Search Space

  • Author

    Sven Türpe

  • Author_Institution
    Fraunhofer Inst. for Secure Inf. Technol. (SIT), Darmstadt, Germany
  • fYear
    2011
  • fDate
    3/1/2011 12:00:00 AM
  • Firstpage
    198
  • Lastpage
    201
  • Abstract
    This position paper outlines a staged approach to search-based application security testing. In the first stage one searches for candidate tests in the input space that have a chance of leading to good security tests. In the second stage one selects individual candidates and uses them to select and parametrize specialized search techniques. This approach has its roots in exploratory security testing. In the first stage, the fitness of tests depends on their ability to provoke vulnerability symptoms at all, and on their relation to other tests in a test suite. In the second stage, the fittest tests are those that come closest to an exploit of a specific type of vulnerability. To evaluate the performance of such a staged approach one might use web application vulnerability scanners as a baseline.
  • Keywords
    "Security","Software","Conferences","Space exploration","Software testing","Software engineering"
  • Publisher
    ieee
  • Conference_Titel
    Software Testing, Verification and Validation Workshops (ICSTW), 2011 IEEE Fourth International Conference on
  • Print_ISBN
    978-1-4577-0019-4
  • Type

    conf

  • DOI
    10.1109/ICSTW.2011.96
  • Filename
    5954410