Vulnerability coverage for adequacy security testing

Vulnerability coverage for adequacy security testing
复制标题

充分安全测试的漏洞覆盖率

DOI:
10.1145/3341105.3374099
复制
发表时间:
2020
期刊:
SAC '20: Proceedings of the 35th Annual ACM Symposium on Applied Computing
影响因子:
--
通讯作者:
Namin, Akbar Siami
Namin, Akbar Siami
中科院分区:
--
文献类型:
--
作者:
Dass, Shuvalaxmi;Namin, Akbar Siami

文献摘要

参考文献

被引文献

相似文献

主流的软件应用程序和工具是可配置的平台,具有大量的参数沿着它们的值。这些参数之间的某些设置和可能的交互可能会加强(或削弱)这些应用程序对某些已知漏洞的安全性和鲁棒性。然而,大量的漏洞报告和与这些工具相关联,使这些工具的详尽测试不可行,对这些漏洞不可行。作为一般软件测试问题的一个实例,要解决的研究问题是被测系统是否健壮和安全。本文介绍了“漏洞覆盖率”的概念,这是一个概念,充分测试给定的应用程序的某些类别的漏洞,报告的国家漏洞数据库(NVD)。衍生的想法是利用通用漏洞评分系统(CVSS)作为一种手段来衡量进化算法生成的测试输入的适应度,然后通过模式匹配识别出与生成的漏洞向量相匹配的漏洞,然后对这些识别出的漏洞进行测试。我们报告了两个进化算法的性能(即,遗传算法和粒子群优化)在生成脆弱性模式向量。
Mainstream software applications and tools are the configurable platforms with an enormous number of parameters along with their values. Certain settings and possible interactions between these parameters may harden (or soften) the security and robustness of these applications against some known vulnerabilities. However, the large number of vulnerabilities reported and associated with these tools make the exhaustive testing of these tools infeasible against these vulnerabilities infeasible. As an instance of general software testing problem, the research question to address is whether the system under test is robust and secure against these vulnerabilities. This paper introduces the idea of "vulnerability coverage," a concept to adequately test a given application for a certain classes of vulnerabilities, as reported by the National Vulnerability Database (NVD). The deriving idea is to utilize the Common Vulnerability Scoring System (CVSS) as a means to measure the fitness of test inputs generated by evolutionary algorithms and then through pattern matching identify vulnerabilities that match the generated vulnerability vectors and then test the system under test for those identified vulnerabilities. We report the performance of two evolutionary algorithms (i.e., Genetic Algorithms and Particle Swarm Optimization) in generating the vulnerability pattern vectors.
Nighthawk:两级遗传随机单元测试数据生成器
DOI: --
发表时间: 2007
期刊: International Conference on Automated Software Engineering
影响因子: --
作者:
J. Andrews;F. C. H. Li;T. Menzies
通讯作者: T. Menzies
使用遗传算法的计算机配置的移动目标环境
DOI: --
发表时间: 2011
期刊: Workshop on Automated Decision Making for Active Cyber Defense
影响因子: --
作者:
Michael B. Crouse;Errin W. Fulp
通讯作者: Errin W. Fulp
TestLocal:局部变量的即时参数化测试
DOI: 10.1145/3297280.3297613
发表时间: 2019
期刊: SAC '19: Proceedings of the 34th ACM/SIGAPP Symposium on Applied Computing
影响因子: --
作者:
Heimlich, Marcel;Namin, Akbar Siami
通讯作者: Namin, Akbar Siami
DOI: 10.1007/s11390-019-1906-z
发表时间: 2019
影响因子: 1.9
作者:
Zheng, Jianjun;Namin, Akbar Siami
通讯作者: Namin, Akbar Siami