首页> 外文会议>International Conference on MEMS, NANO and Smart Systems >A Systematic Approach to Generate and Conduct Destructive Security Test Sets
【24h】

A Systematic Approach to Generate and Conduct Destructive Security Test Sets

机译:一种生成和开展破坏性安全测试集的系统方法

获取原文
获取外文期刊封面目录资料

摘要

Security testing involves two approaches; The question of who should do it has two answers. Standard testing organizations using a traditional approach can perform functional security testing. For example, ensuring that access control mechanisms work as advertised is a classic functional testing exercise. Systematic security testing approaches should be seamlessly incorporated into software engineering curricula and software development process. Traditional software engineering textbooks failed to provide adequate methods and techniques for students and software engineers to bring security engineering approaches to software development process generating secure software as well as correct software. This paper argues that a security testing phase should be added to software development process with systematic approach to generating and conducting destructive security test sets following a complete coverage principle. Software engineers must have formal training on writing secure code. The security testing tasks include penetrating and destructive tests that are different from functional testing tasks currently covered in software engineering textbooks Moreover, component-based development and formal methods could be useful to produce secure code, as well as automatic security checking tools. Some experience of applying security testing principles in our software engineering method teaching is reported.
机译:安全测试涉及两种方法;谁应该有两个答案的问题。使用传统方法的标准测试组织可以执行功能安全测试。例如,确保访问控制机制如识到经典的功能测试练习。系统安全测试方法应无缝地纳入软件工程课程和软件开发过程中。传统的软件工程教科书未能为学生和软件工程师提供足够的方法和技术,为软件开发过程带来安全工程方法生成安全软件以及正确的软件。本文认为,安全测试阶段应以完整的覆盖原理,通过系统的方法来添加到软件开发过程中,以产生和进行破坏性安全测试集。软件工程师必须有正式培训书写安全代码。安全性测试任务包括不同于软件工程教科书目前涵盖的功能测试任务的穿透和破坏性测试,而且基于组件的开发和正式方法可能有助于生成安全代码,以及自动安全检查工具。报道了在我们的软件工程方法教学中应用安全测试原理的一些经验。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号