DocumentCode :
2025593
Title :
Modeling and Testing Secure Web-Based Systems: Application to an Industrial Case Study
Author :
Mallouli, Wissam ; Lallali, Mounir ; Morales, Gerardo ; Cavalli, Ana Rosa
Author_Institution :
CNRS, Inst. Telecom / Telecom SudParis, France
fYear :
2008
fDate :
Nov. 30 2008-Dec. 3 2008
Firstpage :
128
Lastpage :
136
Abstract :
Ensuring that a Web-based system respects its security requirements is a critical issue that has become more and more difficult to perform in these last years. This difficulty is due to the complexity level of such systems as well as their variety and increasing distribution. To guarantee such a respect, we need to test the target Web system by applying a complete set of test cases covering all the possible scenarios. To reach this aim, we first specify the Web system behavior from its functional point of view using IF language. Second, this model is augmented by applying a set of dedicated algorithms to integrate timed security properties specified in Nomad language. This language is well adapted to express security properties with time constraints. Then, we use a dedicated tool called TestGen-IF, to perform an automatic test generation of test cases targeting security purposes. These test sequences are transformed in executable test cases that can be applied on a real Web application. We present in this paper an industrial Web-based system provided by France Telecom as a case study to demonstrate the reliability of our framework.
Keywords :
Internet; formal languages; formal specification; program testing; security of data; France Telecom; IF language; Nomad language; TestGen-IF; Web system behavior; Web-based systems; automatic test generation; executable test cases; industrial Web-based system; industrial case study; security requirements; target Web system; timed security property; Application software; Automata; Automatic testing; Communication industry; Communication system security; Data security; Performance evaluation; System testing; Telecommunications; Time factors; Nomad Language; Security Policy Specification; Security Validation; Test Execution; Test Generation; Timed Automata; Web Applications;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Signal Image Technology and Internet Based Systems, 2008. SITIS '08. IEEE International Conference on
Conference_Location :
Bali
Print_ISBN :
978-0-7695-3493-0
Type :
conf
DOI :
10.1109/SITIS.2008.58
Filename :
4725796
Link To Document :
بازگشت