A fault injection model-oriented testing strategy for component security

作者:Chen Jin fu; Lu Yan sheng; Zhang Wei; Xie Xiao dong
来源:Journal of Central South University of Technology, 2009, 16(2): 258-264.
DOI:10.1007/s11771-009-0044-0

摘要

A fault injection model-oriented testing strategy was proposed for detecting component vulnerabilities. A fault injection model was defined, and the faults were injected into the tested component based on the fault injection model to trigger security exceptions. The testing process could be recorded by the monitoring mechanism of the strategy, and the monitoring information was written into the security log. The component vulnerabilities could be detected by the detecting algorithm through analyzing the security log. Lastly, some experiments were done in an integration testing platform to verify the applicability of the strategy. The experimental results show that the strategy is effective and operable. The detecting rate is more than 90% for vulnerability components.