Communication publiée dans un ouvrage (Colloques, congrès, conférences scientifiques et actes)
A Natural Language Programming Approach for Requirements-based Security Testing
MAI, Xuan Phu; PASTORE, Fabrizio; Göknil, Arda et al.
2018In 29th IEEE International Symposium on Software Reliability Engineering (ISSRE 2018)
Peer reviewed
 

Documents


Texte intégral
Mai-ISSRE-CR-2018_copyrightIEEE.pdf
Postprint Auteur (746.38 kB)
Télécharger

Tous les documents dans ORBilu sont protégés par une licence d'utilisation.

Envoyer vers



Détails



Mots-clés :
System Security Testing; Natural Language Requirements; Natural Language Processing
Résumé :
[en] To facilitate communication among stakeholders, software security requirements are typically written in natural language and capture both positive requirements (i.e., what the system is supposed to do to ensure security) and negative requirements (i.e., undesirable behavior undermining security). In this paper, we tackle the problem of automatically generat- ing executable security test cases from security requirements in natural language (NL). More precisely, since existing approaches for the generation of test cases from NL requirements verify only positive requirements, we focus on the problem of generating test cases from negative requirements. We propose, apply and assess Misuse Case Programming (MCP), an approach that automatically generates security test cases from misuse case specifications (i.e., use case specifications capturing the behavior of malicious users). MCP relies on natural language processing techniques to extract the concepts (e.g., inputs and activities) appearing in requirements specifications and generates executable test cases by matching the extracted concepts to the members of a provided test driver API. MCP has been evaluated in an industrial case study, which provides initial evidence of the feasibility and benefits of the approach.
Centre de recherche :
Interdisciplinary Centre for Security, Reliability and Trust (SnT) > Software Verification and Validation Lab (SVV Lab)
Disciplines :
Sciences informatiques
Auteur, co-auteur :
MAI, Xuan Phu ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
PASTORE, Fabrizio  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Göknil, Arda ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
BRIAND, Lionel ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Co-auteurs externes :
no
Langue du document :
Anglais
Titre :
A Natural Language Programming Approach for Requirements-based Security Testing
Date de publication/diffusion :
2018
Nom de la manifestation :
29th IEEE International Symposium on Software Reliability Engineering (ISSRE 2018)
Date de la manifestation :
October 15-18, 2018
Titre de l'ouvrage principal :
29th IEEE International Symposium on Software Reliability Engineering (ISSRE 2018)
Maison d'édition :
IEEE
ISBN/EAN :
978-1-5386-8321-7
Peer reviewed :
Peer reviewed
Focus Area :
Security, Reliability and Trust
Projet européen :
H2020 - 694277 - TUNE - Testing the Untestable: Model Testing of Complex Software-Intensive Systems
Organisme subsidiant :
CE - Commission Européenne
European Union
Disponible sur ORBilu :
depuis le 10 août 2018

Statistiques


Nombre de vues
1020 (dont 63 Unilu)
Nombre de téléchargements
1102 (dont 36 Unilu)

citations WoS
 
21

Bibliographie


Publications similaires



Contacter ORBilu