Assessing the usefulness of testing for validating the correctness of security risk models based on an industrial case study

Gencer Erdogan, Fredrik Seehusen, Ketil Stølen, Jan Øyvind Aagedal · BIBSYS Brage (BIBSYS (Norway)) · 2014

Abstract. We present the results of an evaluation in which the objective was to assess how useful testing is for validating and gaining condence in the correctness of security risk models. The evaluation is based on a case study where the target system analyzed was a web-based application. The evaluation suggests that the testing was useful in the sense that it yielded new information which resulted in an update of the security risk model after testing.

Read the paper · More papers on PaperTik