The Experts below are selected from a list of 345954 Experts worldwide ranked by ideXlab platform

Eric Dubois - One of the best experts on this subject based on the ideXlab platform.

  • appraisal and reporting of security assurance at operational systems level
    Journal of Systems and Software, 2012
    Co-Authors: Moussa Ouedraogo, Haralambos Mouratidis, Djamel Khadraoui, Eric Dubois
    Abstract:

    In this paper we discuss the issues relating the evaluation and reporting of security assurance of runtime systems. We first highlight the shortcomings of current initiatives in analyzing, evaluating and reporting security assurance information. Then, the paper proposes a set of metrics to help capture and foster a better understanding of the security posture of a system. Our security assurance metric and its reporting depend on whether or not the user of the system has a security background. The evaluation of such metrics is described through the use of theoretical criteria, a Tool Implementation and an application to a case study based on an insurance company network.

Moussa Ouedraogo - One of the best experts on this subject based on the ideXlab platform.

  • appraisal and reporting of security assurance at operational systems level
    Journal of Systems and Software, 2012
    Co-Authors: Moussa Ouedraogo, Haralambos Mouratidis, Djamel Khadraoui, Eric Dubois
    Abstract:

    In this paper we discuss the issues relating the evaluation and reporting of security assurance of runtime systems. We first highlight the shortcomings of current initiatives in analyzing, evaluating and reporting security assurance information. Then, the paper proposes a set of metrics to help capture and foster a better understanding of the security posture of a system. Our security assurance metric and its reporting depend on whether or not the user of the system has a security background. The evaluation of such metrics is described through the use of theoretical criteria, a Tool Implementation and an application to a case study based on an insurance company network.

  • A New Approach to Evaluating Security Assurance
    2011
    Co-Authors: Moussa Ouedraogo, Haralambos Mouratidis, Artur Hecker, Cédric Bonhomme, Djamel Khadraoui, David Preston
    Abstract:

    This paper first analyzes the current gap in the literature in security assurance. It then proposes new metrics for the appraisal of security assurance at runtime. Our metrics are based on key concepts pertinent to gaining confidence on a security mechanism to meet its functions. Such parameters include: security correctness; security effectiveness and the quality of the security verification process. Validation of our approach has been achieved through Tool Implementation, application to case study and the opinion of IT security professionals on its usefulness.

Ruth Breu - One of the best experts on this subject based on the ideXlab platform.

  • Knowledge-based security testing of web applications by logic programming
    International Journal on Software Tools for Technology Transfer, 2017
    Co-Authors: Philipp Zech, Michael Felderer, Ruth Breu
    Abstract:

    This article introduces a new method for knowledge-based security testing by logic programming and the related Tool Implementation for model-based non-functional security testing of web applications. Our method helps to overcome the current prevalent focus on functional instead of non-functional (or negative) requirements as well as the required high level of security knowledge when performing non-functional security testing. It addresses issues like considering non-functional requirements for testing, managing the virtually infinite amount of negative security test cases, advancing non-functional security testing away from its prevalent penetration testing-like style, and making non-functional security testing feasible for testers that are not experts in security via a security knowledge base. The method and its model-based Tool Implementation are evaluated in two studies, which show the method’s effectiveness in detecting vulnerabilities in web applications and thus, also its value in making software system more secure.

  • An Agile and Tool-Supported Methodology for Model-Driven System Testing of Service-Centric Systems
    Advances in Computer and Electrical Engineering, 2013
    Co-Authors: Michael Felderer, Philipp Zech, Ruth Breu
    Abstract:

    In this chapter, the authors present an agile and model-driven system testing methodology for service-centric systems called Telling TestStories. The methodology has a Tool Implementation and is based on separated system, requirements, and test models that can be validated in an integrated way. Test models contain test stories describing test behavior and test data in an integrated way. The underlying testing process is iterative, incremental, and supports a test-driven design on the model level. After a general overview of the artifacts and the testing process, the authors employ the methodology and the Tool Implementation on a case study from the healthcare domain.

Djamel Khadraoui - One of the best experts on this subject based on the ideXlab platform.

  • appraisal and reporting of security assurance at operational systems level
    Journal of Systems and Software, 2012
    Co-Authors: Moussa Ouedraogo, Haralambos Mouratidis, Djamel Khadraoui, Eric Dubois
    Abstract:

    In this paper we discuss the issues relating the evaluation and reporting of security assurance of runtime systems. We first highlight the shortcomings of current initiatives in analyzing, evaluating and reporting security assurance information. Then, the paper proposes a set of metrics to help capture and foster a better understanding of the security posture of a system. Our security assurance metric and its reporting depend on whether or not the user of the system has a security background. The evaluation of such metrics is described through the use of theoretical criteria, a Tool Implementation and an application to a case study based on an insurance company network.

  • A New Approach to Evaluating Security Assurance
    2011
    Co-Authors: Moussa Ouedraogo, Haralambos Mouratidis, Artur Hecker, Cédric Bonhomme, Djamel Khadraoui, David Preston
    Abstract:

    This paper first analyzes the current gap in the literature in security assurance. It then proposes new metrics for the appraisal of security assurance at runtime. Our metrics are based on key concepts pertinent to gaining confidence on a security mechanism to meet its functions. Such parameters include: security correctness; security effectiveness and the quality of the security verification process. Validation of our approach has been achieved through Tool Implementation, application to case study and the opinion of IT security professionals on its usefulness.

Haralambos Mouratidis - One of the best experts on this subject based on the ideXlab platform.

  • appraisal and reporting of security assurance at operational systems level
    Journal of Systems and Software, 2012
    Co-Authors: Moussa Ouedraogo, Haralambos Mouratidis, Djamel Khadraoui, Eric Dubois
    Abstract:

    In this paper we discuss the issues relating the evaluation and reporting of security assurance of runtime systems. We first highlight the shortcomings of current initiatives in analyzing, evaluating and reporting security assurance information. Then, the paper proposes a set of metrics to help capture and foster a better understanding of the security posture of a system. Our security assurance metric and its reporting depend on whether or not the user of the system has a security background. The evaluation of such metrics is described through the use of theoretical criteria, a Tool Implementation and an application to a case study based on an insurance company network.

  • A New Approach to Evaluating Security Assurance
    2011
    Co-Authors: Moussa Ouedraogo, Haralambos Mouratidis, Artur Hecker, Cédric Bonhomme, Djamel Khadraoui, David Preston
    Abstract:

    This paper first analyzes the current gap in the literature in security assurance. It then proposes new metrics for the appraisal of security assurance at runtime. Our metrics are based on key concepts pertinent to gaining confidence on a security mechanism to meet its functions. Such parameters include: security correctness; security effectiveness and the quality of the security verification process. Validation of our approach has been achieved through Tool Implementation, application to case study and the opinion of IT security professionals on its usefulness.