作者
Madeline Cheah, Hoang Nga Nguyen, Jeremy Bryans, Siraj A Shaikh
发表日期
2018
研讨会论文
Information Security Theory and Practice: 11th IFIP WG 11.2 International Conference, WISTP 2017, Heraklion, Crete, Greece, September 28–29, 2017, Proceedings 11
页码范围
113-129
出版商
Springer International Publishing
简介
Vehicles are insecure. To protect such systems, we must begin by identifying any weaknesses. One approach is to apply a systematic security evaluation to the system under test. In this paper we present a method for systematically generating tests based on attack trees. We formalise the attack trees as provably-equivalent process-algebraic processes, then automatically generate tests from the process-algebraic representation. Attack trees may include manual input (and thus so will some test cases) but scriptable test cases are automatically executed. Our approach is inspired by model based testing, but allows for the fact that we do not have a specification of the system under test. We demonstrate this methodology on a case study and find that this is a viable method for automation of systematic security evaluations.
引用总数
201920202021202220232024526472
学术搜索中的文章
M Cheah, HN Nguyen, J Bryans, SA Shaikh - Information Security Theory and Practice: 11th IFIP WG …, 2018