The Experts below are selected from a list of 345954 Experts worldwide ranked by ideXlab platform
Eric Dubois - One of the best experts on this subject based on the ideXlab platform.
-
appraisal and reporting of security assurance at operational systems level
Journal of Systems and Software, 2012Co-Authors: Moussa Ouedraogo, Haralambos Mouratidis, Djamel Khadraoui, Eric DuboisAbstract:In this paper we discuss the issues relating the evaluation and reporting of security assurance of runtime systems. We first highlight the shortcomings of current initiatives in analyzing, evaluating and reporting security assurance information. Then, the paper proposes a set of metrics to help capture and foster a better understanding of the security posture of a system. Our security assurance metric and its reporting depend on whether or not the user of the system has a security background. The evaluation of such metrics is described through the use of theoretical criteria, a Tool Implementation and an application to a case study based on an insurance company network.
Moussa Ouedraogo - One of the best experts on this subject based on the ideXlab platform.
-
appraisal and reporting of security assurance at operational systems level
Journal of Systems and Software, 2012Co-Authors: Moussa Ouedraogo, Haralambos Mouratidis, Djamel Khadraoui, Eric DuboisAbstract:In this paper we discuss the issues relating the evaluation and reporting of security assurance of runtime systems. We first highlight the shortcomings of current initiatives in analyzing, evaluating and reporting security assurance information. Then, the paper proposes a set of metrics to help capture and foster a better understanding of the security posture of a system. Our security assurance metric and its reporting depend on whether or not the user of the system has a security background. The evaluation of such metrics is described through the use of theoretical criteria, a Tool Implementation and an application to a case study based on an insurance company network.
-
A New Approach to Evaluating Security Assurance
2011Co-Authors: Moussa Ouedraogo, Haralambos Mouratidis, Artur Hecker, Cédric Bonhomme, Djamel Khadraoui, David PrestonAbstract:This paper first analyzes the current gap in the literature in security assurance. It then proposes new metrics for the appraisal of security assurance at runtime. Our metrics are based on key concepts pertinent to gaining confidence on a security mechanism to meet its functions. Such parameters include: security correctness; security effectiveness and the quality of the security verification process. Validation of our approach has been achieved through Tool Implementation, application to case study and the opinion of IT security professionals on its usefulness.
Ruth Breu - One of the best experts on this subject based on the ideXlab platform.
-
Knowledge-based security testing of web applications by logic programming
International Journal on Software Tools for Technology Transfer, 2017Co-Authors: Philipp Zech, Michael Felderer, Ruth BreuAbstract:This article introduces a new method for knowledge-based security testing by logic programming and the related Tool Implementation for model-based non-functional security testing of web applications. Our method helps to overcome the current prevalent focus on functional instead of non-functional (or negative) requirements as well as the required high level of security knowledge when performing non-functional security testing. It addresses issues like considering non-functional requirements for testing, managing the virtually infinite amount of negative security test cases, advancing non-functional security testing away from its prevalent penetration testing-like style, and making non-functional security testing feasible for testers that are not experts in security via a security knowledge base. The method and its model-based Tool Implementation are evaluated in two studies, which show the method’s effectiveness in detecting vulnerabilities in web applications and thus, also its value in making software system more secure.
-
An Agile and Tool-Supported Methodology for Model-Driven System Testing of Service-Centric Systems
Advances in Computer and Electrical Engineering, 2013Co-Authors: Michael Felderer, Philipp Zech, Ruth BreuAbstract:In this chapter, the authors present an agile and model-driven system testing methodology for service-centric systems called Telling TestStories. The methodology has a Tool Implementation and is based on separated system, requirements, and test models that can be validated in an integrated way. Test models contain test stories describing test behavior and test data in an integrated way. The underlying testing process is iterative, incremental, and supports a test-driven design on the model level. After a general overview of the artifacts and the testing process, the authors employ the methodology and the Tool Implementation on a case study from the healthcare domain.
Djamel Khadraoui - One of the best experts on this subject based on the ideXlab platform.
-
appraisal and reporting of security assurance at operational systems level
Journal of Systems and Software, 2012Co-Authors: Moussa Ouedraogo, Haralambos Mouratidis, Djamel Khadraoui, Eric DuboisAbstract:In this paper we discuss the issues relating the evaluation and reporting of security assurance of runtime systems. We first highlight the shortcomings of current initiatives in analyzing, evaluating and reporting security assurance information. Then, the paper proposes a set of metrics to help capture and foster a better understanding of the security posture of a system. Our security assurance metric and its reporting depend on whether or not the user of the system has a security background. The evaluation of such metrics is described through the use of theoretical criteria, a Tool Implementation and an application to a case study based on an insurance company network.
-
A New Approach to Evaluating Security Assurance
2011Co-Authors: Moussa Ouedraogo, Haralambos Mouratidis, Artur Hecker, Cédric Bonhomme, Djamel Khadraoui, David PrestonAbstract:This paper first analyzes the current gap in the literature in security assurance. It then proposes new metrics for the appraisal of security assurance at runtime. Our metrics are based on key concepts pertinent to gaining confidence on a security mechanism to meet its functions. Such parameters include: security correctness; security effectiveness and the quality of the security verification process. Validation of our approach has been achieved through Tool Implementation, application to case study and the opinion of IT security professionals on its usefulness.
Haralambos Mouratidis - One of the best experts on this subject based on the ideXlab platform.
-
appraisal and reporting of security assurance at operational systems level
Journal of Systems and Software, 2012Co-Authors: Moussa Ouedraogo, Haralambos Mouratidis, Djamel Khadraoui, Eric DuboisAbstract:In this paper we discuss the issues relating the evaluation and reporting of security assurance of runtime systems. We first highlight the shortcomings of current initiatives in analyzing, evaluating and reporting security assurance information. Then, the paper proposes a set of metrics to help capture and foster a better understanding of the security posture of a system. Our security assurance metric and its reporting depend on whether or not the user of the system has a security background. The evaluation of such metrics is described through the use of theoretical criteria, a Tool Implementation and an application to a case study based on an insurance company network.
-
A New Approach to Evaluating Security Assurance
2011Co-Authors: Moussa Ouedraogo, Haralambos Mouratidis, Artur Hecker, Cédric Bonhomme, Djamel Khadraoui, David PrestonAbstract:This paper first analyzes the current gap in the literature in security assurance. It then proposes new metrics for the appraisal of security assurance at runtime. Our metrics are based on key concepts pertinent to gaining confidence on a security mechanism to meet its functions. Such parameters include: security correctness; security effectiveness and the quality of the security verification process. Validation of our approach has been achieved through Tool Implementation, application to case study and the opinion of IT security professionals on its usefulness.