• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Scopus
  4. SoK: Automated Software Testing for TLS Libraries
 
  • Details
  • Full
Options
2024
Conference Paper
Title

SoK: Automated Software Testing for TLS Libraries

Abstract
Reusable software components, typically integrated as libraries, are a central paradigm of modern software development. By incorporating a library into their software, developers trust in its quality and its correct and complete implementation. Since errors in a library affect all applications using it, there is a need for quality assurance tools such as automated testing that can be used by library and application developers to verify the functionality. In the past decade, many different systems have been published that focus on the automated analysis of TLS implementations for finding bugs and security vulnerabilities. However, all of these systems focus only on few TLS components and lack a common analysis scenario and inter-approach comparisons. Especially, the amount of manual effort required across the whole analysis process to obtain the root cause of an error is often ignored. In this paper, we survey and categorize literature on automated testing approaches for TLS libraries. The results reveal a heterogeneous landscape of approaches with a trade-off between the manual effort required for setup and for result interpretation, along with major deficits in the considered performance metrics. These imply important future directions to advance the current state of protocol test automation.
Author(s)
Swierzy, Ben
Boes, Felix
Pohl, Timo
Bungartz, Christian
Meier, Michael
Fraunhofer-Institut für Kommunikation, Informationsverarbeitung und Ergonomie FKIE  
Mainwork
ARES 2024, 19th International Conference on Availability, Reliability & Security. Proceedings  
Conference
International Conference on Availability, Reliability and Security 2024  
DOI
10.1145/3664476.3670871
Language
English
Fraunhofer-Institut für Kommunikation, Informationsverarbeitung und Ergonomie FKIE  
Keyword(s)
  • automatic testing

  • secondary study

  • security protocols

  • TLS

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024