Risk-driven security testing using risk analysis with threat modeling approach

被引:4
|
作者
Palanivel, Maragathavalli [1 ]
Selvadurai, Kanmani [1 ]
机构
[1] Pondicherry Engn Coll, Dept Informat Technol, Pondicherry, India
来源
SPRINGERPLUS | 2014年 / 3卷
关键词
Security testing; Risk analysis; System states; Risk-driven; Threat modeling; STRIDE; Test suite;
D O I
10.1186/2193-1801-3-754
中图分类号
O [数理科学和化学]; P [天文学、地球科学]; Q [生物科学]; N [自然科学总论];
学科分类号
07 ; 0710 ; 09 ;
摘要
Security testing is a process of determining risks present in the system states and protects them from vulnerabilities. But security testing does not provide due importance to threat modeling and risk analysis simultaneously that affects confidentiality and integrity of the system. Risk analysis includes identification, evaluation and assessment of risks. Threat modeling approach is identifying threats associated with the system. Risk-driven security testing uses risk analysis results in test case identification, selection and assessment to prioritize and optimize the testing process. Threat modeling approach, STRIDE is generally used to identify both technical and non-technical threats present in the system. Thus, a security testing mechanism based on risk analysis results using STRIDE approach has been proposed for identifying highly risk states. Risk metrics considered for testing includes risk impact, risk possibility and risk threshold. Risk threshold value is directly proportional to risk impact and risk possibility. Risk-driven security testing results in reduced test suite which in turn reduces test case selection time. Risk analysis optimizes the test case selection and execution process. For experimentation, the system models namely LMS, ATM, OBS, OSS and MTRS are considered. The performance of proposed system is analyzed using Test Suite Reduction Rate (TSRR) and FSM coverage. TSRR varies from 13.16 to 21.43% whereas FSM coverage is achieved up to 91.49%. The results show that the proposed method combining risk analysis with threat modeling identifies states with high risks to improve the testing efficiency.
引用
收藏
页码:1 / 14
页数:14
相关论文
共 50 条
  • [1] Threat and Risk-Driven Security Requirements Engineering
    Schmidt, Holger
    INTERNATIONAL JOURNAL OF MOBILE COMPUTING AND MULTIMEDIA COMMUNICATIONS, 2011, 3 (01) : 35 - 50
  • [2] Towards Risk-Driven Security Testing of Service Centric Systems
    Zech, Philipp
    Felderer, Michael
    Breu, Ruth
    2012 12TH INTERNATIONAL CONFERENCE ON QUALITY SOFTWARE (QSIC), 2012, : 140 - 143
  • [3] SPARTA: Security & Privacy Architecture through Risk-driven Threat Assessment
    Sion, Laurens
    Van Landuyt, Dimitri
    Yskout, Koen
    Joosen, Wouter
    2018 IEEE 15TH INTERNATIONAL CONFERENCE ON SOFTWARE ARCHITECTURE COMPANION (ICSA-C 2018), 2018, : 89 - 92
  • [4] A risk-driven security analysis method and modelling language
    Kearney, P.
    Bruegger, L.
    BT TECHNOLOGY JOURNAL, 2007, 25 (01) : 141 - 153
  • [5] Design Decisions in the Development of a Graphical Language for Risk-Driven Security Testing
    Erdogan, Gencer
    Stolen, Ketil
    RISK ASSESSMENT AND RISK-DRIVEN QUALITY ASSURANCE, RISK 2016, 2017, 10224 : 99 - 114
  • [6] RISK-DRIVEN SOFTWARE TESTING AND RELIABILITY
    Schneidewind, Norman F.
    INTERNATIONAL JOURNAL OF RELIABILITY QUALITY & SAFETY ENGINEERING, 2007, 14 (02): : 99 - 132
  • [7] Risk-driven development of security-critical systems using UMLsec
    Jürjens, J
    INFORMATION TECHNOLOGY: SELECTED TUTORIALS, 2004, 157 : 21 - 53
  • [8] Risk-driven conceptual modeling of outsourcing decisions
    van Eck, P
    Wieringa, R
    Gordijn, J
    CONCEPTUAL MODELING - ER 2004, PROCEEDINGS, 2004, 3288 : 709 - 723
  • [9] Risk-driven security metrics for an Android smartphone application
    Savola R.M.
    Kylänpaä M.
    Abie H.
    Savola, Reijo M. (reijo.savola@vtt.fi), 1600, Inderscience Publishers (15): : 297 - 324
  • [10] A risk-driven approach for subsurface site characterization
    de Barros, F. P. J.
    Rubin, Y.
    WATER RESOURCES RESEARCH, 2008, 44 (01)