会议论文详细信息
Doctoral Symposium of ESSoS 2012.
Risk-driven Security Testing versus Test-driven Security Risk Analysis ?
计算机科学;
Gencer Erdogan1,2 Supervised by: Ketil Stølen1,2
Others  :  http://ceur-ws.org/Vol-834/paper1_essosds2012.pdf
PID  :  33643
学科分类:计算机科学(综合)
来源: CEUR
PDF
【 摘 要 】

It is important to clearly distinguish the combinations of security testing and security risk analysis depending on whether it is viewed from a security testing perspective or a security risk analysis perspective. The main focus in the former view is security testing in which test objectives are to be achieved, while the main focus in the latter view is security risk analysis with the aim to fulfill risk acceptance criteria. The literature’s lack of addressing this distinction is accompanied with the lack of addressing two immediate problems within this context, namely the gap between high-level security risk analysis models and low-level security test cases, and the consideration of investable effort. We present initial ideas for methods that address these problems followed by an industrial case study evaluation in which we have gathered interesting results.

【 预 览 】
附件列表
Files Size Format View
Risk-driven Security Testing versus Test-driven Security Risk Analysis ? 365KB PDF download
  文献评价指标  
  下载次数:12次 浏览次数:15次