To main content

Learning From Software Security Testing

Abstract

Software security testing tools and methodologies are presently abundant, and the question no longer seems to be ``if to test'' for security, but rather ``where and when to test'' and ``then what?''. In this paper we present a review of security testing literature, and propose a software security testing scheme that exploits an intra-organisational repository of discovered vulnerabilities that closes the loop after the testing of one application is complete, providing useful input to the next application to be tested.
Read the publication

Category

Academic chapter

Language

English

Author(s)

Affiliation

  • SINTEF Digital / Software Engineering, Safety and Security

Year

2008

Publisher

IEEE (Institute of Electrical and Electronics Engineers)

Book

IEEE International Conference on Software Testing Verification and Validation Workshop, 2008. ICSTW '08, Lillehammer 9-11 April, 2008

ISBN

9780769533889

Page(s)

286 - 294

View this publication at Norwegian Research Information Repository