Comparison of SETAM with security use case and security misuse case: A software security testing study

Zhanwei Hui, Song Huang · Wuhan University Journal of Natural Sciences · 2012

A software security testing behavior model, SETAM, was proposed in our previous work as the integrated model for describing software security testing requirements behavior, which is not only compatible with security functions and latent typical misuse behaviors, but also with the interaction of them. In this paper, we analyze the differences between SETAM with security use case and security misuse case in different types of security test requirements. To illustrate the effectiveness of SETAM, we compare them in a practical case study by the number of test cases and the number of faults detected by them. The results show that SETAM could decrease about 34.87% use cases on average, and the number of faults detected by SETAM increased by 71.67% in average, which means that our model can detect more faults with fewer test cases for software security testing.

Read the paper · More papers on PaperTik