...
首页> 外文期刊>Journal of Theoretical and Applied Information Technology >TEST CASE SELECTION FOR PENETRATION TESTING IN MOBILE CLOUD COMPUTING APPLICATIONS: A PROPOSED TECHNIQUE
【24h】

TEST CASE SELECTION FOR PENETRATION TESTING IN MOBILE CLOUD COMPUTING APPLICATIONS: A PROPOSED TECHNIQUE

机译:在移动云计算应用程序中进行渗透测试的测试案例选择:一种建议的技术

获取原文
   

获取外文期刊封面封底 >>

       

摘要

The extensive use of mobile applications in terms of user?s number and size of diverse data has introduced additional security threats which make uncovering these vulnerabilities complex for testers. Testers use certain types of software security testing to detect software vulnerabilities, particularly penetration testing. Test case selection is an essential phase of penetration testing, especially when testing complex and large applications. Multiple techniques have been proposed for selecting test cases to be used in penetration testing. In general, the majority of such techniques select a set of test cases that cover the designated paths and fit well with the user requirements. This study reviews existing techniques and models that are used for test case selection. Methods, strengths and weaknesses are the main factors that are presented in this study. This study shows that offloading, that is, the technology used in mobile cloud computing applications, has been disregarded by existing techniques and models for test case selection. Therefore, this study proposes an enhanced test case selection technique for penetration testing. This proposed technique considers offloading parameters when selecting test cases to improve coverage paths and reflect user preferences in terms of cloud and mobile priority percentages. Moreover, test cases for both mobile and cloud in the mobile cloud computing applications are considered to be selected in list of test cases to be executed. Besides, user preferences feature is provided in the selection process to reflect the importance of each parties, cloud and mobile sides of the application under test. The proposed technique will improve the security of mobile cloud computing applications by exposing the possible vulnerabilities from both mobile and cloud sides application.
机译:就用户的数量和不同数据的大小而言,移动应用程序的广泛使用带来了额外的安全威胁,这使测试人员很难发现这些漏洞。测试人员使用某些类型的软件安全测试来检测软件漏洞,尤其是渗透测试。测试用例的选择是渗透测试的重要阶段,尤其是在测试复杂和大型应用程序时。已经提出了多种技术来选择要在渗透测试中使用的测试用例。通常,大多数此类技术会选择一组涵盖指定路径并完全符合用户要求的测试用例。这项研究回顾了用于测试案例选择的现有技术和模型。方法,优点和缺点是本研究提出的主要因素。这项研究表明,分流(即移动云计算应用程序中使用的技术)已被测试用例选择的现有技术和模型所忽略。因此,本研究提出了一种用于渗透测试的增强测试用例选择技术。这项提议的技术在选择测试用例时会考虑卸载参数,以改善覆盖范围并根据云和移动优先级百分比反映用户的偏好。此外,在移动云计算应用程序中用于移动和云的测试用例都被认为是在要执行的测试用例列表中选择的。此外,在选择过程中提供了用户首选项功能,以反映被测应用程序各方,云和移动端的重要性。所提出的技术将通过暴露来自移动和云端应用程序的可能漏洞来提高移动云计算应用程序的安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号