DocumentCode
2660223
Title
Practical Security Testing of Telecommunications Software--A Case Study
Author
Savola, Reijo ; Karppinen, Kaarina
Author_Institution
VTT Tech. Res. Centre of Finland, Espoo
fYear
2007
fDate
13-19 May 2007
Firstpage
7
Lastpage
7
Abstract
In order to obtain evidence about the security strength in products we need automated information security analysis, validation, evaluation and testing approaches. Unfortunately, no widely accepted practical approaches are available. Information security testing of software-intensive and telecommunications systems typically relies heavily on the experience of the security professionals. In this study, we argue that security requirements are within the focus of the information security testing process. Information security requirements can be based on iterative risk, threat and vulnerability analyses, and technical and architectural information. We discuss security testing process, security objectives and security requirements from the basis of the experiences of a security testing case study project.
Keywords
security of data; telecommunication computing; telecommunication security; automated information security analysis; information security testing process; iterative risk; security testing; telecommunications software; threat analyses; vulnerability analyses; Automatic testing; Computer bugs; Information analysis; Information security; Manufacturing industries; Monitoring; Protocols; Risk analysis; Software testing; System testing;
fLanguage
English
Publisher
ieee
Conference_Titel
Telecommunications, 2007. AICT 2007. The Third Advanced International Conference on
Conference_Location
Morne
Print_ISBN
0-7695-2843-0
Electronic_ISBN
0-7695-2843-0
Type
conf
DOI
10.1109/AICT.2007.37
Filename
4215228
Link To Document