Security Testing by Telling TestStories.
Michael Felderer, Berthold Agreiter, Ruth Breu, Álvaro Armenteros · 2010
Abstract: Security testing is very important to assure acertain level ofreliability in asystem. On the system level, security testing has to guarantee that security requirements such as confidentiality, integrity, authentication, authorization, availability and non-repudiation hold. In this paper, we present an approach to system level security testing of service oriented systems that evaluates security requirements. Our approach is based on the Telling TestStories methodology for model–driven system testing. After the elicitation of security requirements, we define asystem and atest model. The test model is then transformed to executable test code. We show how traceability between all artifacts can be established and how the tests can be executed focusing on security relevant aspects. All steps are explained based on an industrial case study. 1