Security Test Generation by Answer Set Programming

被引:1
|
作者
Zech, Philipp [1 ]
Felderer, Michael [1 ]
Katt, Basel [1 ]
Breu, Ruth [1 ]
机构
[1] Univ Innsbruck, Inst Comp Sci, A-6020 Innsbruck, Tyrol, Austria
来源
2014 EIGHTH INTERNATIONAL CONFERENCE ON SOFTWARE SECURITY AND RELIABILITY | 2014年
基金
奥地利科学基金会;
关键词
Security Testing; Test Generation; Software Testing; Security Engineering; Logic Programming; Knowledge Representation; Answer Set Programming; CONSTRAINT; VERIFICATION;
D O I
10.1109/SERE.2014.22
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Security testing still is a hard task, especially if focusing on non-functional security testing. The two main reasons behind this are, first, at the most a lack of the necessary knowledge required for security testing; second, managing the almost infinite amount of negative test cases, which result from potential security risks. To the best of our knowledge, the issue of the automatic incorporation of security expert knowledge, e.g., known vulnerabilities, exploits and attacks, in the process of security testing is not well considered in the literature. Furthermore, well-known "de facto" security testing approaches, like fuzzing or penetration testing, lack systematic procedures regarding the order of execution of test cases, which renders security testing a cumbersome task. Hence, in this paper we propose a new method for generating negative security tests by logic programming, which applies a risk analysis to establish a set of negative requirements for later test generation.
引用
收藏
页码:88 / 97
页数:10
相关论文
共 50 条
  • [21] Matchmaking with Answer Set Programming
    Gebser, Martin
    Glase, Thomas
    Sabuncu, Orkunt
    Schaub, Torsten
    LOGIC PROGRAMMING AND NONMONOTONIC REASONING (LPNMR 2013), 2013, 8148 : 342 - 347
  • [22] Achievements in answer set programming
    Lifschitz, Vladimir
    THEORY AND PRACTICE OF LOGIC PROGRAMMING, 2017, 17 (5-6) : 961 - 973
  • [23] Applications of Answer Set Programming
    Erdem, Esra
    Gelfond, Michael
    Leone, Nicola
    AI MAGAZINE, 2016, 37 (03) : 53 - 68
  • [24] Answer Set Programming at a Glance
    Brewka, Gerhard
    Eiter, Thomas
    Truszczynski, Miroslaw
    COMMUNICATIONS OF THE ACM, 2011, 54 (12) : 92 - 103
  • [25] Automata and Answer Set Programming
    Marek, Victor
    Remmel, Jeffrey B.
    LOGICAL FOUNDATIONS OF COMPUTER SCIENCE, 2009, 5407 : 323 - +
  • [26] Cooperating answer set programming
    Van Nieuwenborgh, Davy
    Heymans, Stijn
    Vermeir, Dirk
    LOGIC PROGRAMMING, PROCEEDINGS, 2006, 4079 : 226 - 241
  • [27] Answer set programming unleashed!
    Schaub, Torsten
    Woltran, Stefan
    KUNSTLICHE INTELLIGENZ, 2018, 32 (2-3): : 105 - 108
  • [28] Definitions in answer set programming
    Erdogan, ST
    Lifschitz, V
    LOGIC PROGRAMMING, PROCEEDINGS, 2003, 2916 : 483 - 484
  • [29] Answer Set Programming: A Primer
    Eiter, Thomas
    Ianni, Giovambattista
    Krennwallner, Thomas
    REASONING WEB: SEMANTIC TECHNOLOGIES FOR INFORMATION SYSTEMS, 2009, 5689 : 40 - +
  • [30] Sketched Answer Set Programming
    Paramonov, Sergey
    Bessiere, Christian
    Dries, Anton
    De Raedt, Luc
    2018 IEEE 30TH INTERNATIONAL CONFERENCE ON TOOLS WITH ARTIFICIAL INTELLIGENCE (ICTAI), 2018, : 694 - 701