Cargando…

Risk-driven security testing using risk analysis with threat modeling approach

Security testing is a process of determining risks present in the system states and protects them from vulnerabilities. But security testing does not provide due importance to threat modeling and risk analysis simultaneously that affects confidentiality and integrity of the system. Risk analysis inc...

Descripción completa

Detalles Bibliográficos
Autores principales: Palanivel, Maragathavalli, Selvadurai, Kanmani
Formato: Online Artículo Texto
Lenguaje:English
Publicado: Springer International Publishing 2014
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC4320241/
https://www.ncbi.nlm.nih.gov/pubmed/25674480
http://dx.doi.org/10.1186/2193-1801-3-754
_version_ 1782356091661713408
author Palanivel, Maragathavalli
Selvadurai, Kanmani
author_facet Palanivel, Maragathavalli
Selvadurai, Kanmani
author_sort Palanivel, Maragathavalli
collection PubMed
description Security testing is a process of determining risks present in the system states and protects them from vulnerabilities. But security testing does not provide due importance to threat modeling and risk analysis simultaneously that affects confidentiality and integrity of the system. Risk analysis includes identification, evaluation and assessment of risks. Threat modeling approach is identifying threats associated with the system. Risk-driven security testing uses risk analysis results in test case identification, selection and assessment to prioritize and optimize the testing process. Threat modeling approach, STRIDE is generally used to identify both technical and non-technical threats present in the system. Thus, a security testing mechanism based on risk analysis results using STRIDE approach has been proposed for identifying highly risk states. Risk metrics considered for testing includes risk impact, risk possibility and risk threshold. Risk threshold value is directly proportional to risk impact and risk possibility. Risk-driven security testing results in reduced test suite which in turn reduces test case selection time. Risk analysis optimizes the test case selection and execution process. For experimentation, the system models namely LMS, ATM, OBS, OSS and MTRS are considered. The performance of proposed system is analyzed using Test Suite Reduction Rate (TSRR) and FSM coverage. TSRR varies from 13.16 to 21.43% whereas FSM coverage is achieved up to 91.49%. The results show that the proposed method combining risk analysis with threat modeling identifies states with high risks to improve the testing efficiency. ELECTRONIC SUPPLEMENTARY MATERIAL: The online version of this article (doi:10.1186/2193-1801-3-754) contains supplementary material, which is available to authorized users.
format Online
Article
Text
id pubmed-4320241
institution National Center for Biotechnology Information
language English
publishDate 2014
publisher Springer International Publishing
record_format MEDLINE/PubMed
spelling pubmed-43202412015-02-11 Risk-driven security testing using risk analysis with threat modeling approach Palanivel, Maragathavalli Selvadurai, Kanmani Springerplus Research Security testing is a process of determining risks present in the system states and protects them from vulnerabilities. But security testing does not provide due importance to threat modeling and risk analysis simultaneously that affects confidentiality and integrity of the system. Risk analysis includes identification, evaluation and assessment of risks. Threat modeling approach is identifying threats associated with the system. Risk-driven security testing uses risk analysis results in test case identification, selection and assessment to prioritize and optimize the testing process. Threat modeling approach, STRIDE is generally used to identify both technical and non-technical threats present in the system. Thus, a security testing mechanism based on risk analysis results using STRIDE approach has been proposed for identifying highly risk states. Risk metrics considered for testing includes risk impact, risk possibility and risk threshold. Risk threshold value is directly proportional to risk impact and risk possibility. Risk-driven security testing results in reduced test suite which in turn reduces test case selection time. Risk analysis optimizes the test case selection and execution process. For experimentation, the system models namely LMS, ATM, OBS, OSS and MTRS are considered. The performance of proposed system is analyzed using Test Suite Reduction Rate (TSRR) and FSM coverage. TSRR varies from 13.16 to 21.43% whereas FSM coverage is achieved up to 91.49%. The results show that the proposed method combining risk analysis with threat modeling identifies states with high risks to improve the testing efficiency. ELECTRONIC SUPPLEMENTARY MATERIAL: The online version of this article (doi:10.1186/2193-1801-3-754) contains supplementary material, which is available to authorized users. Springer International Publishing 2014-12-19 /pmc/articles/PMC4320241/ /pubmed/25674480 http://dx.doi.org/10.1186/2193-1801-3-754 Text en © Palanivel and Selvadurai; licensee Springer. 2014 This article is published under license to BioMed Central Ltd. This is an Open Access article distributed under the terms of the Creative Commons Attribution License (http://creativecommons.org/licenses/by/4.0), which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly credited.
spellingShingle Research
Palanivel, Maragathavalli
Selvadurai, Kanmani
Risk-driven security testing using risk analysis with threat modeling approach
title Risk-driven security testing using risk analysis with threat modeling approach
title_full Risk-driven security testing using risk analysis with threat modeling approach
title_fullStr Risk-driven security testing using risk analysis with threat modeling approach
title_full_unstemmed Risk-driven security testing using risk analysis with threat modeling approach
title_short Risk-driven security testing using risk analysis with threat modeling approach
title_sort risk-driven security testing using risk analysis with threat modeling approach
topic Research
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC4320241/
https://www.ncbi.nlm.nih.gov/pubmed/25674480
http://dx.doi.org/10.1186/2193-1801-3-754
work_keys_str_mv AT palanivelmaragathavalli riskdrivensecuritytestingusingriskanalysiswiththreatmodelingapproach
AT selvaduraikanmani riskdrivensecuritytestingusingriskanalysiswiththreatmodelingapproach