• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. Combining risk analysis and security testing
 
  • Details
  • Full
Options
2014
Conference Paper
Title

Combining risk analysis and security testing

Abstract
A systematic integration of risk analysis and security testing allows for optimizing the test process as well as the risk assessment itself. The result of the risk assessment, i.e. the identified vulnerabilities, threat scenarios and unwanted incidents, can be used to guide the test identification and may complement requirements engineering results with systematic information concerning the threats and vulnerabilities of a system and their probabilities and consequences. This information can be used to weight threat scenarios and thus help identifying the ones that need to be treated and tested more carefully. On the other side, risk-based testing approaches can help to optimize the risk assessment itself by gaining empirical knowledge on the existence of vulnerabilities, the applicability and consequences of threat scenarios and the quality of countermeasures. This paper outlines a tool-based approach for risk-based security testing that combines the notion of risk-assessment with a pattern-based approach for automatic test generation relying on test directives and strategies and shows how results from the testing are systematically fed back into the risk assessment.
Author(s)
Großmann, Jürgen  
Fraunhofer-Institut für Offene Kommunikationssysteme FOKUS  
Schneider, Martin
Fraunhofer-Institut für Offene Kommunikationssysteme FOKUS  
Viehmann, Johannes  
Fraunhofer-Institut für Offene Kommunikationssysteme FOKUS  
Wendland, Marc-Florian  
Fraunhofer-Institut für Offene Kommunikationssysteme FOKUS  
Mainwork
Leveraging applications of formal methods, verification and validation. Specialized techniques and applications. 6th international symposium, ISoLA 2014. Vol.2  
Project(s)
RASEN  
MIDAS  
Funder
European Commission EC  
European Commission EC  
Conference
International Symposium on Leveraging Applications of Formal Methods, Verification and Validation (ISoLA) 2014  
International School on Tool-Based Rigorous Engineering of Software Systems (STRESS) 2014  
File(s)
Download (834.07 KB)
Rights
Use according to copyright law
DOI
10.1007/978-3-662-45231-8_23
10.24406/h-386531
Language
English
Fraunhofer-Institut für Offene Kommunikationssysteme FOKUS  
  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024