Application penetration testing
Herbert H. Thompson · IEEE Security & Privacy · 2005
Security bugs' hidden nature is why we need specific, focused application-security testing techniques, testing that defies the traditional model of verifying an application's specification and instead identifies the unspecified and insecure side-effects of "correct" application functionality. I examine application penetration testing - software testing that's specifically designed to hunt down security vulnerabilities