Automated security test generation with formal threat models

D Xu, M Tu, M Sanford, L Thomas… - IEEE transactions on …, 2012 - ieeexplore.ieee.org
Security attacks typically result from unintended behaviors or invalid inputs. Security testing
is labor intensive because a real-world program usually has too many invalid inputs. It is …

[PDF][PDF] Research on software security testing

G Tian-yang, S Yin-Sheng, F You-yuan - International Journal of Computer …, 2010 - Citeseer
Software security testing is an important means to ensure software security and trustiness.
This paper first mainly discusses the definition and classification of software security testing …

A test-based security certification scheme for web services

M Anisetti, CA Ardagna, E Damiani… - ACM Transactions on the …, 2013 - dl.acm.org
The Service-Oriented Architecture (SOA) paradigm is giving rise to a new generation of
applications built by dynamically composing loosely coupled autonomous services. Clients …

Model-based security testing using umlsec: A case study

J Jürjens - Electronic Notes in Theoretical Computer Science, 2008 - Elsevier
Designing and implementing security-critical systems correctly is very difficult. In practice,
most vulnerabilities arise from bugs in implementations. We present work towards …

虚拟校园三维全景漫游技术研究

杨琳, 赵建民, 朱信忠, 徐慧英, 郑国强 - 计算机工程与科学, 2007 - joces.nudt.edu.cn
本文对全景漫游技术进行了讨论. 全景漫游技术中需要解决三个问题: 全景图的生成,
漫游空间的编辑和浏览器的设计. 基于两张圆鱼眼图像生成单张球面全景图 …

Scalable and effective test generation for role-based access control systems

A Masood, R Bhatti, A Ghafoor… - IEEE Transactions on …, 2009 - ieeexplore.ieee.org
Conformance testing procedures for generating tests from the finite state model
representation of Role-Based Access Control (RBAC) policies are proposed and evaluated …

[PDF][PDF] Анализ подходов к верификации функций безопасности и мобильности

АС Косачев, ВН Пономаренко - М.: Триумф, 2004 - ispras.ru
Компьютерная безопасность и мобильность являются одними из самых актуальных
областей исследования и разработок. В первую очередь это связано с тем, что всё …

Web 服务安全性测试技术研究

施寅生, 邓世伟, 谷天阳 - 计算机工程与科学, 2007 - joces.nudt.edu.cn
Web 服务的应用越来越广泛, Web 服务中的安全缺陷与漏洞也在不断增多, Web
服务安全性问题日益突出. Web 服务安全性测试是保证Web 服务软件安全性 …

Application programming interface security validation for system integration testing

SE Joyce, NM Miles, MT Desai, YW Martin… - US Patent …, 2021 - Google Patents
Techniques are provided to implement application programming interface (API) security
validation testing for system integration testing (SIT) in a continuous integration environment …

[PDF][PDF] Scalable and effective test generation for access control systems that employ RBAC policies

A Masood, A Ghafoor, A Mathur - Purdue University, 2006 - researchgate.net
Abstract Representation of Role Based Access Control (RBAC) policies as finite state
models and three conformance testing procedures for generating tests from these models …