Skip to Main content Skip to Navigation
Journal articles

An Approach for Guiding Developers in the Choice of Security Solutions and in the Generation of Concrete Test Cases

Abstract : This paper tackles the problems of choosing security solutions and writing concrete security test cases for software, which are two tasks of the software life cycle requiring time, expertise and experience. We propose in this paper a method, based upon the notion of knowledge base, for helping developers devise more secure applications from the threat modelling step up to the testing one. The first stage of the approach consists of the acquisition and integration of publicly available security data into a data store. This one is used to assist developers in the design of attack-defense trees expressing the attacker possibilities to compromise an application and the defenses that may be implemented. These defenses are given under the form of security pattern combinations, a security pattern being a generic and reusable solution to design more secure applications. In the second stage, these trees are used to guide developers in the test case generation. Test verdicts show whether an application is vulnerable to the threats modelled by an ADTree and whether the consequences of the chosen security patterns are observed from the application (a consequence leading to some observable events partly showing that a pattern is correctly implemented). We applied this approach to web applications and evaluated it on 24 participants. The results are very encouraging in terms of the two criteria: comprehensibility and effectiveness.
Document type :
Journal articles
Complete list of metadata
Contributor : Sébastien Salva Connect in order to contact the contributor
Submitted on : Wednesday, September 8, 2021 - 6:52:40 PM
Last modification on : Monday, September 13, 2021 - 3:43:11 PM


Files produced by the author(s)


Distributed under a Creative Commons Attribution 4.0 International License




Sébastien Salva, Loukmen Regainia. An Approach for Guiding Developers in the Choice of Security Solutions and in the Generation of Concrete Test Cases. Software Quality Journal, Springer Verlag, In press, ⟨10.1007/s11219-018-9438-2⟩. ⟨hal-02019145⟩



Record views


Files downloads