• DocumentCode
    1592913
  • Title

    Keynote Paper: Search Based Software Testing for Software Security: Breaking Code to Make it Safer

  • Author

    Antoniol, Giuliano

  • Author_Institution
    SOCCER Lab., DGIGL Ecole Polytech. de Montreal, Montreal, QC
  • fYear
    2009
  • Firstpage
    87
  • Lastpage
    100
  • Abstract
    Ensuring security of software and computerized systems is a pervasive problem plaguing companies and institutions and affecting many areas of modern life. Software vulnerability may jeopardize information confidentiality and cause software failure leading tocatastrophic threats to humans or severe economic losses. Size, complexity, extensibility, connectivity and the search for cheap systems make it very hard or even impossible to manually tackle vulnerability detection. Search based software testing attempts to solve two aspects of the cost - vulnerabilityproblem. First, it´s cheaper because itis far less labor intensive when compared to traditional testing techniques. As a result, it can be used to more thoroughly test software and reduce the risk that a vulnerability slips into production code. Also, search based software testing can be specifically tailored to tackle the subset of well known security vulnerabilities responsible for most security threats. This paper is divided into two parts. It examines promising search based testing approaches to detecting software vulnerabilities, and then presents some of the most interesting open research problems.
  • Keywords
    data privacy; program testing; security of data; code breaking; computerized system security; cost-vulnerability problem; information confidentiality; pervasive problem; search based software testing; software failure; software security; software vulnerability; Application software; Computer security; Costs; Data security; Humans; Production; Software performance; Software safety; Software systems; Software testing; high dependability software; search based software testing; vulnerability exposure;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Software Testing, Verification and Validation Workshops, 2009. ICSTW '09. International Conference on
  • Conference_Location
    Denver, CO
  • Print_ISBN
    978-1-4244-4356-7
  • Type

    conf

  • DOI
    10.1109/ICSTW.2009.12
  • Filename
    4976374