首页> 外文会议>International Conference on Hybrid Intelligent Systems >CSTS: A Prototype Tool for Testing COM Component Security
【24h】

CSTS: A Prototype Tool for Testing COM Component Security

机译:CSTS:用于测试COM组件安全性的原型工具

获取原文
获取外文期刊封面目录资料

摘要

The automatic testing tools of component security bring great effect on component-based software engineering, and they can effectively ensure the security of component-based software. A prototype tool named CSTS (component security testing system) is designed and implemented to test the security of the widely-used COTS (Commercial-off-the-Shelf) Microsoft COM (component object model) component. CSTS, a GUI (graphical user interface) software, adopts both static and dynamic testing based on fault injection and dynamic monitoring. Firstly, CSTS analyzes component type information and statically injects parameter faults into interface methods. Secondly, environment faults such as memory fault, file fault and process fault are injected into the tested component when the component is driven. Dynamic monitoring mechanism can monitor the running process of component and analyze the component security exceptions. Some commercial components were tested in the CSTS. The experimental results show that CSTS is effective and operable.
机译:组件安全的自动测试工具对基于组件的软件工程产生了很大的影响,他们可以有效地确保基于组件的软件的安全性。设计并实现了名为CSTS(组件安全测试系统)的原型工具,以测试广泛使用的COTS(商业离职)Microsoft COM(组件对象模型)组件的安全性。 CSTS,GUI(图形用户界面)软件,采用基于故障注入和动态监控的静态和动态测试。首先,CSTS分析组件类型信息并静态将参数故障注入接口方法。其次,在驱动组件时将环境故障如内存故障,文件故障,文件故障和过程故障注入到测试组件中。动态监控机制可以监控组件的运行过程并分析组件安全性异常。在CSTS中测试了一些商业组分。实验结果表明,CSTS是有效和可操作的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号