Risk-driven security testing using risk analysis with threat modeling approach

被引:4
|
作者
Palanivel, Maragathavalli [1 ]
Selvadurai, Kanmani [1 ]
机构
[1] Pondicherry Engn Coll, Dept Informat Technol, Pondicherry, India
来源
SPRINGERPLUS | 2014年 / 3卷
关键词
Security testing; Risk analysis; System states; Risk-driven; Threat modeling; STRIDE; Test suite;
D O I
10.1186/2193-1801-3-754
中图分类号
O [数理科学和化学]; P [天文学、地球科学]; Q [生物科学]; N [自然科学总论];
学科分类号
07 ; 0710 ; 09 ;
摘要
Security testing is a process of determining risks present in the system states and protects them from vulnerabilities. But security testing does not provide due importance to threat modeling and risk analysis simultaneously that affects confidentiality and integrity of the system. Risk analysis includes identification, evaluation and assessment of risks. Threat modeling approach is identifying threats associated with the system. Risk-driven security testing uses risk analysis results in test case identification, selection and assessment to prioritize and optimize the testing process. Threat modeling approach, STRIDE is generally used to identify both technical and non-technical threats present in the system. Thus, a security testing mechanism based on risk analysis results using STRIDE approach has been proposed for identifying highly risk states. Risk metrics considered for testing includes risk impact, risk possibility and risk threshold. Risk threshold value is directly proportional to risk impact and risk possibility. Risk-driven security testing results in reduced test suite which in turn reduces test case selection time. Risk analysis optimizes the test case selection and execution process. For experimentation, the system models namely LMS, ATM, OBS, OSS and MTRS are considered. The performance of proposed system is analyzed using Test Suite Reduction Rate (TSRR) and FSM coverage. TSRR varies from 13.16 to 21.43% whereas FSM coverage is achieved up to 91.49%. The results show that the proposed method combining risk analysis with threat modeling identifies states with high risks to improve the testing efficiency.
引用
收藏
页码:1 / 14
页数:14
相关论文
共 50 条
  • [31] Risk-Driven Design of Perception Systems
    Corso, Anthony L.
    Katz, Sydney M.
    Innes, Craig
    Du, Xin
    Ramamoorthy, Subramanian
    Kochenderfer, Mykel J.
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 35 (NEURIPS 2022), 2022,
  • [32] Increasing test efficiency by risk-driven model-based testing
    Gebizli, Ceren Sahin
    Kirkici, Abdulhadi
    Sozer, Hasan
    JOURNAL OF SYSTEMS AND SOFTWARE, 2018, 144 : 356 - 365
  • [33] Risk-Driven Security Metrics Development for an e-Health IoT Application
    SavoIa, Reijo M.
    Savolainen, Pekka
    Evesti, Antti
    Abie, Habtamu
    Sihvonen, Markus
    2015 INFORMATION SECURITY FOR SOUTH AFRICA - PROCEEDINGS OF THE ISSA 2015 CONFERENCE, 2015,
  • [34] Risk-Driven Revision of Requirements Models
    Alrajeh, Dalal
    van Lamsweerde, Axel
    Kramer, Jeff
    Russo, Alessandra
    Uchitel, Sebastian
    2016 IEEE/ACM 38TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING (ICSE), 2016, : 855 - 865
  • [35] Systemic Risk-Driven Portfolio Selection
    Capponi, Agostino
    Rubtsov, Alexey
    OPERATIONS RESEARCH, 2022, 70 (03) : 1598 - 1612
  • [36] Risk-Driven Security Metrics in Agile Software Development - An Industrial Pilot Study
    Savola, Reijo M.
    Fruhwirth, Christian
    Pietikainen, Ari
    JOURNAL OF UNIVERSAL COMPUTER SCIENCE, 2012, 18 (12) : 1679 - 1702
  • [37] Risk-driven migration and the collective-risk social dilemma
    Chen, Xiaojie
    Szolnoki, Attila
    Perc, Matjaz
    PHYSICAL REVIEW E, 2012, 86 (03):
  • [38] A risk-driven approach to designing privacy-enhanced secure applications
    Van Herreweghen, E
    INFORMATION SECURITY MANAGEMENT, EDUCATION AND PRIVACY, 2004, 148 : 265 - 280
  • [40] Security Risk Management in E-commerce Systems: A Threat-driven Approach
    Affia, Abasi-amefon O.
    Matulevicius, Raimundas
    Nolte, Alexander
    BALTIC JOURNAL OF MODERN COMPUTING, 2020, 8 (02): : 213 - 240