Security Assessment Techniques for Software Assurance - a "Virtual Team" Approach

被引:0
|
作者
Isaacs, Derek [1 ]
机构
[1] Boecore Inc, Colorado Springs, CO USA
关键词
Information assurance; software assurance; software testing; virtual systems;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Software Assurance / Software "Security" often imposes a requirement that applications be tested in a "live" (or as close to as is practicable) system - this often includes the surrounding implementation environment as greater fidelity is needed for critical application testing and implementation confidence levels. Merely installing the software and performing a "short list" verification activity is insufficient - actual " hands on" execution of the software is needed - and when this can be done in a simulated live environment - a higher confidence level can be extended to the application target of evaluation (TOE) for implementation. This task is daunting not because of the nature of the testing - but of the need to setup and subsequently tear-down systems to participate in the performance of these tests. Fortunately - there are tools and techniques for testing application security - using a reduced set of hardware and yet maintaining operational fidelity. Virtual Machines (VM)'s and virtual network environments (team architectures) offer a method for providing this level of testing confidence while allowing for a greater variety of tests and test participant systems. This paper presents a series of architectures and scenarios proposed to implement such a testing environment that retains the viability (and fidelity) of a 'real-world' network environment while providing an isolated and restricted test and analysis area. This is shown through a series of scenarios and VM Team setups (scenario players) in a virtual machine based environment. This approach allows a number of benefits: Isolation of the testing environment Focus on the Target of Evaluation (TOE) for testing Capture and provide metrics on tool and technique usage and impact Provide limits and mitigation of risk and liability issues for the TOE The VM environment also offers a unique opportunity to simulate interactions between various known systems under test (TOE)'s in a 'replicated' environment. A set of proposed scenarios and an environmental architecture, including toolsets and targets of evaluation (TOE) systems is proposed. The applicability of the VM 'team' systems approach is discussed through a suite of scenarios designed to illustrate System evaluation, monitoring, and detection.
引用
收藏
页码:500 / 506
页数:7
相关论文
共 50 条
  • [31] An improved network security situation assessment approach in software defined networks
    Fan, Zhijie
    Xiao, Ya
    Nayak, Amiya
    Tan, Chengxiang
    PEER-TO-PEER NETWORKING AND APPLICATIONS, 2019, 12 (02) : 295 - 309
  • [32] Development of a software security assessment instrument to reduce software security risk
    Gilliam, DP
    Kelly, JC
    Powell, JD
    Bishop, M
    PROCEEDINGS OF THE TENTH IEEE INTERNATIONAL WORKSHOPS ON ENABLING TECHNOLOGIES: INFRASTRUCTURE FOR COLLABORATIVE ENTERPRISES, 2001, : 144 - 149
  • [33] Security assurance assessment methodology for hybrid clouds
    Hudic, Aleksandar
    Smith, Paul
    Weippl, Edgar R.
    COMPUTERS & SECURITY, 2017, 70 : 723 - 743
  • [34] Optimising virtual team leadership in Global Software Development
    Tuffley, D.
    IET SOFTWARE, 2012, 6 (03) : 176 - 184
  • [35] Towards supporting software assurance assessments by detecting security patterns
    Bunke, Michaela
    Sohr, Karsten
    SOFTWARE QUALITY JOURNAL, 2020, 28 (04) : 1711 - 1753
  • [36] Security Testing as part of Software Quality Assurance: Principles and Challenges
    Mallouli, Wissam
    2022 IEEE 15TH INTERNATIONAL CONFERENCE ON SOFTWARE TESTING, VERIFICATION AND VALIDATION WORKSHOPS (ICSTW 2022), 2022, : 29 - 29
  • [37] Towards supporting software assurance assessments by detecting security patterns
    Michaela Bunke
    Karsten Sohr
    Software Quality Journal, 2020, 28 : 1711 - 1753
  • [38] Multi-center quality assurance: The team approach
    Villarreal, C. Lizette
    Fernandez, Miguel C.
    Gardner, Melody
    CLINICAL TOXICOLOGY, 2013, 51 (07) : 693 - 693
  • [39] A Method for Rapid Creation of a Virtual Software Development Team
    Vavpotic, Damjan
    Furlan, Stefan
    Bajec, Marko
    INFORMATION SYSTEMS DEVELOPMENT: CHALLENGES IN PRACTICE, THEORY AND EDUCATION, VOLS 1AND 2, 2009, : 461 - 470
  • [40] Development of Intelligent Virtual Assistant for Software Testing Team
    Itkin, Iosif
    Novikov, Andrey
    Yavorskiy, Rostislav
    2019 COMPANION OF THE 19TH IEEE INTERNATIONAL CONFERENCE ON SOFTWARE QUALITY, RELIABILITY AND SECURITY (QRS-C 2019), 2019, : 126 - 129