To main content

Assessing the Usefulness of Testing for Validating the Correctness of Security Risk Models Based on an Industrial Case Study

Abstract

We present the results of an evaluation in which the objective was to assess how useful testing is for validating and gaining confidence in the correctness of security risk models. The evaluation is based on a case study where the target system analyzed was a web-based application. The evaluation suggests that the testing was useful in the sense that it yielded new information which resulted in an update of the security risk model after testing.
Oppdragsgiver: Norwegian Research Council
Read publication

Category

Report

Client

  • SINTEF AS / 102002253

Language

Other

Author(s)

Affiliation

  • SINTEF Digital / Sustainable Communication Technologies
  • Diverse norske bedrifter og organisasjoner

Year

2014

Publisher

SINTEF

Issue

A26187

ISBN

9788214053555

View this publication at Cristin