2015
DOI: 10.4018/ijsse.2015040105
|View full text |Cite
|
Sign up to set email alerts
|

Assessing the Usefulness of Testing for Validating and Correcting Security Risk Models Based on Two Industrial Case Studies

Abstract: The authors present the results of an evaluation in which the objective was to assess how useful testing is for validating and correcting security risk models. The evaluation is based on two industrial case studies. In the first case study the authors analyzed a multilingual financial Web application, while in the second case study they analyzed a mobile financial application. In both case studies, the testing yielded new information which was not found in the risk assessment phase. In particular, in the first… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1

Citation Types

0
3
0

Publication Types

Select...
2
1

Relationship

1
2

Authors

Journals

citations
Cited by 3 publications
(3 citation statements)
references
References 11 publications
0
3
0
Order By: Relevance
“…6, no. 2, 2015) [43]. This thesis presents the camera-ready version of the paper because the published version was not available at the time of writing.…”
Section: Paper 5: Assessing the Usefulness Of Testing For Validating And Correcting Security Risk Models Based On Two Industrial Case Stumentioning
confidence: 99%
“…6, no. 2, 2015) [43]. This thesis presents the camera-ready version of the paper because the published version was not available at the time of writing.…”
Section: Paper 5: Assessing the Usefulness Of Testing For Validating And Correcting Security Risk Models Based On Two Industrial Case Stumentioning
confidence: 99%
“…With RBST and TBRA there are at least two different ways how risk assessment and security testing can interact, but of course it should be possible to combine both, too. [11] uses a combination of both approaches, but it does not propose any technique or detailed guideline for how to update the risk model based on the test results.…”
Section: State Of the Artmentioning
confidence: 99%
“…There have been several publications about this approach, e.g. [12] [13], but there is no general applicable methodology and not much tool support.…”
Section: Security Testing In Combination With Risk Assessmentmentioning
confidence: 99%