A Fault Injection Approach Based on Operational Profile

Fanping Zeng, Juan Li, Ling Li, Xufa Wang · 2009

Now that most security violations (may cause vulnerabilities) are triggered by the way the software including potential vulnerabilities interacts with malicious users and theist abnormal runtime environment, we generate test cases from the aspect of user of target software. We develop the operational profile to generate the test cases and the requirement specification of security is generated to check the data collected from the experiment. This approach emulates the faults as accurately as possible in order to trigger new vulnerabilities, and it can inject faults both in the random and determine mode. Test cases are injected during the running application, without instrument the code.

Read the paper · More papers on PaperTik