• DocumentCode
    2013940
  • Title

    Training Security Assurance Teams Using Vulnerability Injection

  • Author

    Fonseca, J. ; Vieira, Marco ; Madeira, Henrique ; Henrique, M.

  • Author_Institution
    CISUC, Polithecnic Inst. of Guarda, Guarda, Portugal
  • fYear
    2008
  • fDate
    15-17 Dec. 2008
  • Firstpage
    297
  • Lastpage
    304
  • Abstract
    Writing secure Web applications is a complex task. In fact, a vast majority of Web applications are likely to have security vulnerabilities that can be exploited using simple tools like a common Web browser. This represents a great danger as the attacks may have disastrous consequences to organizations, harming their assets and reputation. To mitigate these vulnerabilities, security code inspections and penetration tests must be conducted by well-trained teams during the development of the application. However, effective code inspections and testing takes time and cost a lot of money, even before any business revenue. Furthermore, software quality assurance teams typically lack the knowledge required to effectively detect security problems. In this paper we propose an approach to quickly and effectively train security assurance teams in the context of web application development. The approach combines a novel vulnerability injection technique with relevant guidance information about the most common security vulnerabilities to provide a realistic training scenario. Our experimental results show that a short training period is sufficient to clearly improve the ability of security assurance teams to detect vulnerabilities during both code inspections and penetration tests.
  • Keywords
    Internet; security of data; software quality; Web browser; code inspections; penetration tests; software quality assurance; training security assurance teams; vulnerability injection technique; Application software; Costs; Data security; Information security; Inspection; Performance evaluation; Quality assurance; Software quality; Testing; Writing; Security; Training; Vulnerability Injection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Dependable Computing, 2008. PRDC '08. 14th IEEE Pacific Rim International Symposium on
  • Conference_Location
    Taipei
  • Print_ISBN
    978-0-7695-3448-0
  • Electronic_ISBN
    978-0-7695-3448-0
  • Type

    conf

  • DOI
    10.1109/PRDC.2008.43
  • Filename
    4725309