A new protocol security testing method is proposed based on a fault model. The method utilizes the mutation analysis based on the specification of constructed type algebra. Mutant operators are designed to restrict the possible fault sets in protocol; then mutants are generated and equivalent mutants are deleted; and test cases are finally constructed based on resulting mutants. Compared with existing methods
the proposed method can effectively solve several problems in current protocol security testing
such as neglecting the protocol dataflow
infinite fault sets
the lack of the mechanism to judge results
and so on. It is beneficial to the quantification and appraisal of testing to limit the possible fault sets of protocol. The method can pointedly be used to construct test cases and to judge test results
and improves testing capacity.
关键词
Keywords
references
KAKSONEN R. A Functional method for assessing protocol implementation security [EB/OL]. [2009-01-20].http:∥www.vtt.fi/inf/pdf/publications/2001/P447.pdf
SHU Xiao, DENG Lijun. Integrated TCP/IP protocol software testing for vulnerability detection [C]∥Proceedings of the 2003 International Conference on Computer Networks and Mobile Computing. Los Alamitos, CA, USA: IEEE Computer Society, 2003: 311-319.
MARQUIS S, DEAN T, KNIGHT S. SCL: a language for security testing of network applications [C]∥Proceedings of the 2005 Conference of the Centre for Advanced Studies on Collaborative Research. Lebanon, IN, USA: IBM Press, 2005:155-164.
ALLEN W H, DOU C. A model-based approach to the security testing of network protocol implementations [C]∥31st IEEE Conference on Local Computer Networks. Piscataway, NJ, USA: IEEE, 2006:1008-1015.