An Approach for Guiding Developers in the Choice of Security Solutions and in the Generation of Concrete Test Cases - Université Clermont Auvergne Accéder directement au contenu
Article Dans Une Revue Software Quality Journal Année : 2019

An Approach for Guiding Developers in the Choice of Security Solutions and in the Generation of Concrete Test Cases

Résumé

This paper tackles the problems of choosing security solutions and writing concrete security test cases for software, which are two tasks of the software life cycle requiring time, expertise and experience. We propose in this paper a method, based upon the notion of knowledge base, for helping developers devise more secure applications from the threat modelling step up to the testing one. The first stage of the approach consists of the acquisition and integration of publicly available security data into a data store. This one is used to assist developers in the design of attack-defense trees expressing the attacker possibilities to compromise an application and the defenses that may be implemented. These defenses are given under the form of security pattern combinations, a security pattern being a generic and reusable solution to design more secure applications. In the second stage, these trees are used to guide developers in the test case generation. Test verdicts show whether an application is vulnerable to the threats modelled by an ADTree and whether the consequences of the chosen security patterns are observed from the application (a consequence leading to some observable events partly showing that a pattern is correctly implemented). We applied this approach to web applications and evaluated it on 24 participants. The results are very encouraging in terms of the two criteria: comprehensibility and effectiveness.
Fichier principal
Vignette du fichier
document.pdf (1.36 Mo) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)

Dates et versions

hal-02019145 , version 1 (08-09-2021)

Licence

Paternité

Identifiants

Citer

Sébastien Salva, Loukmen Regainia. An Approach for Guiding Developers in the Choice of Security Solutions and in the Generation of Concrete Test Cases. Software Quality Journal, In press, ⟨10.1007/s11219-018-9438-2⟩. ⟨hal-02019145⟩
122 Consultations
148 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More