The need for functional security testing

被引:0
|
作者
Axelrod, C. Warren [1 ]
机构
[1] Delta Risk, P.O. Box 234030, Great Neck, NY 11023, United States
来源
CrossTalk | 2011年 / 24卷 / 02期
关键词
Software testing;
D O I
暂无
中图分类号
学科分类号
摘要
Despite extensive testing of application functionality and security, we see many instances of software, when attacked or during normal operation, performing adversely in ways that were not anticipated. In large part, this is due to software assurance staff not testing fully for negative functionality, that is, ensuring that applications do not do what they are not supposed to. There are many reasons for this, including the relative enormity of the task, the pressure to implement quickly, and the lack of qualified testers. In this article, we will examine these issues and suggest ways in which we can achieve some measure of assurance that applications will not behave inappropriately under a broad range of conditions.
引用
收藏
页码:17 / 21
相关论文
共 50 条
  • [31] Security testing and resilience
    Cavalli, Ana Rosa
    2021 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE TESTING, VERIFICATION AND VALIDATION WORKSHOPS (ICSTW 2021), 2021, : 124 - 124
  • [32] Security Testing: A Survey
    Felderer, Michael
    Buechler, Matthias
    Johns, Martin
    Brucker, Achim D.
    Breu, Ruth
    Pretschner, Alexander
    ADVANCES IN COMPUTERS, VOL 101, 2016, 101 : 1 - 51
  • [33] Software security testing
    Potter, B
    McGraw, G
    IEEE SECURITY & PRIVACY, 2004, 2 (05) : 81 - 85
  • [34] A Framework for Security Testing
    Gupta, Daya
    Chatterjee, Kakali
    Jaiswal, Shruti
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS (ICCSA 2013), PT III, 2013, 7973 : 187 - 198
  • [35] MICROCOMPUTER TESTING SECURITY
    LUNDGREN, TD
    JOURNAL OF COMPUTER INFORMATION SYSTEMS, 1994, 34 (04) : 77 - 80
  • [36] On the Automation of Security Testing
    Wotawa, Franz
    PROCEEDINGS OF 2016 INTERNATIONAL CONFERENCE ON SOFTWARE SECURITY AND ASSURANCE (ICSSA), 2016, : 11 - 16
  • [37] Why enterprises need to adopt ‘need-to-know’ security
    Rangel A.
    Computer Fraud and Security, 2019, 2019 (12): : 9 - 12
  • [38] TESTING IN PARALLEL A Need for Practical Regression Testing
    Zhang, Zhenyu
    Tong, Zijian
    Gao, Xiaopeng
    ICSOFT 2010: PROCEEDINGS OF THE FIFTH INTERNATIONAL CONFERENCE ON SOFTWARE AND DATA TECHNOLOGIES, VOL 2, 2010, : 344 - 348
  • [39] Security Attack Testing (SAT) - testing the security of information systems at design time
    Mouratidis, Haralambos
    Giorgini, Paolo
    INFORMATION SYSTEMS, 2007, 32 (08) : 1166 - 1183
  • [40] Need for a Paradigm Shift in Security: Adopting Human Security in Pakistan
    Syed, Maria
    IPRI JOURNAL, 2014, 14 (02): : 79 - 97