A Fault Injection Approach Based on Operational Profile
Fanping Zeng, Juan Li, Ling Li, Xufa Wang · 2009
Now that most security violations (may cause vulnerabilities) are triggered by the way the software including potential vulnerabilities interacts with malicious users and theist abnormal runtime environment, we generate test cases from the aspect of user of target software. We develop the operational profile to generate the test cases and the requirement specification of security is generated to check the data collected from the experiment. This approach emulates the faults as accurately as possible in order to trigger new vulnerabilities, and it can inject faults both in the random and determine mode. Test cases are injected during the running application, without instrument the code.