An approach of security testing for third-party component based on state mutation

An approach of security testing for third-party component based on state mutation
复制标题

DOI:
10.1002/sec.1189
复制
发表时间:
2016-10
期刊:
Secur. Commun. Networks
影响因子:
--
通讯作者:
Jinfu Chen;Jiamei Chen;Rubing Huang;Yuchi Guo;Yongzhao Zhan
Jinfu Chen;Jiamei Chen;Rubing Huang;Yuchi Guo;Yongzhao Zhan
中科院分区:
其他
文献类型:
--
作者:
Jinfu Chen;Jiamei Chen;Rubing Huang;Yuchi Guo;Yongzhao Zhan

文献摘要

被引文献

相似文献

研究一种针对第三方组件的有效安全测试方法至关重要。在本文中,为了有效触发第三方组件的隐含漏洞,提出了一种基于状态变异的第三方组件安全测试方法。首先,将组件的可执行方法序列转换为扩展有限状态机。然后,根据条件冲突和行为冲突的特征,提出了两种测试用例生成算法,即操作冲突序列生成算法和条件冲突序列生成算法,用于生成行为和条件冲突的不可达序列。运行这些冲突序列。此外,提出了安全检测算法来检测第三方组件的隐含漏洞,进而获得组件安全测试报告。最后,基于所提出的方法进行了一些实验,实验结果表明该方法能够有效检测第三方组件的安全异常。版权所有©2015约翰威立父子有限公司
It is essential to study an effective approach of security testing for third-party component. In this paper, to effectively trigger implicit vulnerabilities of third-party components, an approach of security testing for third-party component is proposed based on state mutation. To start with, executable method sequences of components are transformed into extended finite state machine. Then, according to characteristics of condition conflict and behavior conflict, two test case generation algorithms are addressed, that is, Operations Conflict Sequences Generation Algorithm and Conditions Conflict Sequences Generation Algorithm, which are designed to generate inaccessible sequences of behavior and condition conflicts. These conflict sequences are run. Furthermore, the security detecting algorithms are addressed to detect implicit vulnerabilities of third-party components, and then, testing report of component security is obtained. In the end, some experiments are conducted on the basis of the proposed approach, and the experimental results show that the proposed approach can effectively detect security exceptions of third-party components. Copyright © 2015 John Wiley & Sons, Ltd.