Risk-driven security testing using risk analysis with threat modeling approach

被引:4
|
作者
Palanivel, Maragathavalli [1 ]
Selvadurai, Kanmani [1 ]
机构
[1] Pondicherry Engn Coll, Dept Informat Technol, Pondicherry, India
来源
SPRINGERPLUS | 2014年 / 3卷
关键词
Security testing; Risk analysis; System states; Risk-driven; Threat modeling; STRIDE; Test suite;
D O I
10.1186/2193-1801-3-754
中图分类号
O [数理科学和化学]; P [天文学、地球科学]; Q [生物科学]; N [自然科学总论];
学科分类号
07 ; 0710 ; 09 ;
摘要
Security testing is a process of determining risks present in the system states and protects them from vulnerabilities. But security testing does not provide due importance to threat modeling and risk analysis simultaneously that affects confidentiality and integrity of the system. Risk analysis includes identification, evaluation and assessment of risks. Threat modeling approach is identifying threats associated with the system. Risk-driven security testing uses risk analysis results in test case identification, selection and assessment to prioritize and optimize the testing process. Threat modeling approach, STRIDE is generally used to identify both technical and non-technical threats present in the system. Thus, a security testing mechanism based on risk analysis results using STRIDE approach has been proposed for identifying highly risk states. Risk metrics considered for testing includes risk impact, risk possibility and risk threshold. Risk threshold value is directly proportional to risk impact and risk possibility. Risk-driven security testing results in reduced test suite which in turn reduces test case selection time. Risk analysis optimizes the test case selection and execution process. For experimentation, the system models namely LMS, ATM, OBS, OSS and MTRS are considered. The performance of proposed system is analyzed using Test Suite Reduction Rate (TSRR) and FSM coverage. TSRR varies from 13.16 to 21.43% whereas FSM coverage is achieved up to 91.49%. The results show that the proposed method combining risk analysis with threat modeling identifies states with high risks to improve the testing efficiency.
引用
收藏
页码:1 / 14
页数:14
相关论文
共 50 条
  • [41] Risk-driven Online Testing and Test Case Diversity Analysis for ML-enabled Critical Systems
    Adigun, Jubril Gbolahan
    Huck, Tom Philip
    Camilli, Matteo
    Felderer, Michael
    2023 IEEE 34TH INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING, ISSRE, 2023, : 344 - 354
  • [42] A Risk-Driven Probabilistic Approach to Quantify Resilience in Power Distribution Systems
    Poudyal, Abodh
    Dubey, Anamika
    Poudel, Shiva
    2022 17TH INTERNATIONAL CONFERENCE ON PROBABILISTIC METHODS APPLIED TO POWER SYSTEMS (PMAPS), 2022,
  • [43] A Threat-Driven Approach to Modeling a Campus Network Security
    Naagas, Marlon A.
    Palaoag, Thelma D.
    PROCEEDINGS OF 2018 6TH INTERNATIONAL CONFERENCE ON COMMUNICATIONS AND BROADBAND NETWORKING (ICCBN 2018), 2018, : 6 - 12
  • [44] A risk-driven design model for embedded system
    Dong, Y
    Li, MS
    SECOND ASIA-PACIFIC CONFERENCE ON QUALITY SOFTWARE, PROCEEDINGS, 2001, : 204 - 208
  • [45] New multi-objective approach for dynamic risk-driven intrusion responses
    Katar, Chaker
    Badreddine, Ahmed
    FRONTIERS OF COMPUTER SCIENCE, 2020, 14 (01) : 230 - 232
  • [46] Collective-risk social dilemma on the risk-driven dynamic networks
    Hu, Min
    Chen, Wei
    CHAOS SOLITONS & FRACTALS, 2024, 184
  • [47] Threat scenario-based security risk analysis using use case modeling in information systems
    Kim, Young-Gab
    Cha, Sungdeok
    SECURITY AND COMMUNICATION NETWORKS, 2012, 5 (03) : 293 - 300
  • [48] FRiCS: A Framework for Risk-driven Cloud Selection
    Arias-Cabarcos, Patricia
    Almenarez, Florina
    Diaz-Sanchez, Daniel
    Marin, Andres
    MPS'18: PROCEEDINGS OF THE 2ND INTERNATIONAL WORKSHOP ON MULTIMEDIA PRIVACY AND SECURITY, 2018, : 18 - 26
  • [49] A risk-driven multi-objective evolutionary approach for selecting software requirements
    Aruan Amaral
    Gledson Elias
    Evolutionary Intelligence, 2019, 12 : 421 - 444
  • [50] A risk-driven multi-objective evolutionary approach for selecting software requirements
    Amaral, Aruan
    Elias, Gledson
    EVOLUTIONARY INTELLIGENCE, 2019, 12 (03) : 421 - 444