GI LogoGI Logo
  • Anmelden
Digitale Bibliothek
    • Gesamter Bestand

      • Bereiche & Sammlungen
      • Titel
      • Autor
      • Erscheinungsdatum
      • Schlagwort
    • Diese Sammlung

      • Titel
      • Autor
      • Erscheinungsdatum
      • Schlagwort
Digital Bibliothek der Gesellschaft für Informatik e.V.
GI-DL
    • English
    • Deutsch
  • Deutsch 
    • English
    • Deutsch
Dokumentanzeige 
  •   Startseite
  • Fachbereiche
  • Softwaretechnik (SWT)
  • Softwaretechnik-Trends
  • Softwaretechnik-Trends 32(2) - 2012
  • Dokumentanzeige
JavaScript is disabled for your browser. Some features of this site may not work without it.
  •   Startseite
  • Fachbereiche
  • Softwaretechnik (SWT)
  • Softwaretechnik-Trends
  • Softwaretechnik-Trends 32(2) - 2012
  • Dokumentanzeige

Fuzzing: Testing Security in Maintenance Projects

Autor(en):
Simon, Frank [DBLP] ;
Simon, Daniel [DBLP]
Zusammenfassung
Frank Simon, Daniel Simon SQS Software Quality Systems AG, Stollwerckstraße 11, 51149 Cologne, Germany Email: frank.simon|[email protected] Abstract: New trends in IT industry impose increasingly requirements on openness and interoperability via networks to enterprise software systems. As a consequence, more and more legacy applications are made available via interfaces more openly through mobile and insecure networks, thereby inducing security risks the initial designs have never had to account for. In this paper, we show how a highly automatable black-box method called fuzzing for testing security can be integrated into testing processes to increase interfaces of legacy application in terms of security profiles. tem for mobile communication ­ as example ­ has not only to be tested for its own but might motivate deeper testing of directly connected components. For a more systematic view on these implicit testing adjustments testing can be refined into four steps (a more general approach can be found in [2]: 1. Identification of test objects (What artefacts relevant for project success?) 2. Identification of quality attributes (What properties should the artefacts have?) 3. Determination of corresponding test activities to ensure artefacts having particular attributes 4. Clustering of test activities into test stages that can be executed in conjunction This paper focuses the following aspect: Adding new interfaces creates new test objects as well as it produces new or at least adjusted priorities for quality attributes requiring additional test activities on all test stages. Quality attributes for software can be taken from ISO 25000 family of standards. [3] In particular when adding new service interfaces to legacy applications the first time, security should be seen as one of the top priorities. Security is defined in the ISO 25010 standard as the Degree to which a product or system protects information and data so that persons or other products or systems have the degree of data access appropriate to their types and levels of authorization.
  • Vollständige Referenz
  • BibTeX
Simon, F. & Simon, D., (2012). Fuzzing: Testing Security in Maintenance Projects.   Softwaretechnik-Trends: Vol. 32, No. 2. Köllen Druck & Verlag GmbH. (S. 61-62). DOI: 10.1007/BF03323481
@article{mci/Simon2012,
author = {Simon, Frank AND Simon, Daniel},
title = {Fuzzing: Testing Security in Maintenance Projects},
journal = {Softwaretechnik-Trends},
volume = {32},
number = {2},
year = {2012},
,
pages = { 61-62 } ,
doi = { 10.1007/BF03323481 }
}
DateienGroesseFormatAnzeige
40568_2013_Article_BF03323481.pdf174.4Kb PDF Öffnen

Sollte hier kein Volltext (PDF) verlinkt sein, dann kann es sein, dass dieser aus verschiedenen Gruenden (z.B. Lizenzen oder Copyright) nur in einer anderen Digital Library verfuegbar ist. Versuchen Sie in diesem Fall einen Zugriff ueber die verlinkte DOI: 10.1007/BF03323481

Haben Sie fehlerhafte Angaben entdeckt? Sagen Sie uns Bescheid: Feedback abschicken

Mehr Information

DOI: 10.1007/BF03323481
ISSN: 0720-8928
Datum: 2012
Sprache: en (en)
Typ: Text/Journal Article

Keywords

  • Test Process
  • Security Test
  • Legacy Application
  • Brute Force Method
  • Software Product Quality
Sammlungen
  • Softwaretechnik-Trends 32(2) - 2012 [47]

Zur Langanzeige


Über uns | FAQ | Hilfe | Impressum | Datenschutz

Gesellschaft für Informatik e.V. (GI), Kontakt: Geschäftsstelle der GI
Diese Digital Library basiert auf DSpace.

 

 


Über uns | FAQ | Hilfe | Impressum | Datenschutz

Gesellschaft für Informatik e.V. (GI), Kontakt: Geschäftsstelle der GI
Diese Digital Library basiert auf DSpace.