To main content

Evaluation of the CORAL Approach for Risk-Driven Security Testing Based on an Industrial Case Study

Abstract

The CORAL approach is a model‐based method to security testing employing risk
assessment to help security testers select and design test cases based on the available risk picture. In this report we present experiences from using CORAL in an industrial case. The results indicate that CORAL supports security testers in producing risk models that are valid and threat scenarios that are directly testable. This, in turn, helps testers to select and design test cases according to the most severe security risks posed on the system under test.
Oppdragsgiver: Norwegian Research Council

Category

Report

Client

  • SINTEF AS / 102002253

Language

English

Author(s)

Affiliation

  • SINTEF Digital / Sustainable Communication Technologies
  • Diverse norske bedrifter og organisasjoner

Year

2015

Publisher

SINTEF

Issue

A27097

ISBN

9788214059076

View this publication at Cristin