How useful is software fault injection for evaluating the security of COTS products?
J. Reynolds, Matt Bishop, A. K. Ghosh, J. Whittaker · 2005
Software fault injection (SFI) is a controversial methodfor identifying errors and improving software. Manyrespected researchers believe the method holds promise,including the members on our panel, although withcareful qualifications. On the other hand, COTS softwaremanufacturers tend to view the method with skepticismfor several reasons. One problem is the difficulty inverifying that injected faults are representative of realworld faults. Another is that SFI may not be as efficient inidentifying errors in software as more conventionaltesting. The three panelists explored wide-rangingalternatives to the industry view.