A threat model-driven security testing approach for web application

2Citations
Citations of this article
14Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Web applications have been playing a more and more essential role in daily life; hence, the problem of security is gaining more focus, and consequently a great deal of research on web application security testing has been developed. Among them, however, the most have been concentrated on the testing procedure arranged after the completion of the implementation process. In this paper, we propose a threat model-driven security testing approach for detecting threats, which consists of four activities: building threat tree, according to the attack pattern, against the threats web applications may confront; deriving a security testing sequence from thread model; deriving security testing data from UML sequence diagram parameters for extracting test inputs; generating executable security test case. Also, we proposed an algorithm for generating security testing sequences and conducted an empirical study to show the feasibility and effectiveness of our approach. © 2012 Springer-Verlag Berlin Heidelberg.

Cite

CITATION STYLE

APA

Yan, B., Li, X., & Du, Z. (2013). A threat model-driven security testing approach for web application. Communications in Computer and Information Science, 332, 158–168. https://doi.org/10.1007/978-3-642-34447-3_14

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free